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Prepared for: The Board of Directors 


Customers with offshore engagements 
(follow-up) 


Confidential 


25 April, 2016 


Summary 


e  Onthe Board Meeting the 5 April, 2016, the Board of Directors assigned the CEO to update the Board 
on the situation regarding the Group’s status in relation to offshore countries. 


• There are several cases when the bank, ог its subsidiaries, have business relations with customers 
located in offshore jurisdictions. This can be accepted when it is proven and documented that the 
customers have a legitimate reason to reside in such place. Examples of such cases are when the 
customer's identity is acknowledged, the source of funds unquestionable and the risk for money 
laundering can be managed properly. 


e То enable a relevant business decision whether a customer can be accepted or not, it is essential that 
each customer's full identity, the purpose and nature of the relationship with the bank, source of funds, 
etc. ("Know Your Customer’, KYC) is carried out and properly documented. Therefore, the KYC on all 
customers domiciled in a country that can be classified as offshore, is revised by responsible Business 
Area. 


“ Compliance will advise and support the business to achieve an updated and relevant KYC. Moreover, 
Compliance will monitor the area during Q3/ 2016 and thereafter report status to the Board. 


1. Background 


On April 3, 2016, media informed globally about a law firm in Panama (Mossack Fonseca) that has provided 
advice, facilitated and created corporate structures with the purposes to facilitate tax evasion, corruption and 
other acts of money laundering for customers throughout the world. Mossack Fonseca is one of a number law 
firms that provides these services. A number of political leaders and other celebrities were pointed out with name 
and position, as were a number of banks that have assisted their customers to come in touch with the law firm. In 
Sweden the bank Nordea was pointed out officially by media, but in the leaked documents the also name 
"Swedbank" is mentioned over 700 times. There is currently no information on what context Swedbank has been 
mentioned in. 


Following the attention, the S-FSA on April 12, 2016, asked for information from Swedbank and the other 3 large 
banks in Sweden. The answer, based on information provided by the Business Areas attached, was submitted to 
the S-FSA on April 15, 2016, as requested. The questions were targeting the Group's and the Group's customers’ 
involvement with offshore jurisdictions on a broad scope, as well as Swedbank's internal control structure and 
framework regarding risks related to offshore business. . It can be presumed that the S-FSA will come back with 
follow-up questions in the near future. 


2. What the investigation has shown so far 


All Business Areas have gone through their customer bases to compile customers located in jurisdictions that 
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Swedbank ф 


could be classified as "offshore"!. Further, customers located in other low-tax jurisdictions are also included, e.g. 
customers located in Luxembourg (although it could be questioned if Luxembourg is an offshore company, as it is 
not classified as such according to the list held by the IMF). 


The compilation shows that there are a number of companies located in the above mentioned countries, for a 
more detailed report please refer to Appendices A — D (optional reading). Moreover, it is clear that some of the 
customers have “shell companies” in their company structure. Although, all Business Areas affirm that their 
customers have a legitimate purpose for their structure and that the reason for being located in an offshore 
jurisdiction is neither tax evasion nor any other illegal activity. They also confirm that they have a relevant know 
your customer (KYC) information documented on the customers, incl. identification of ultimate beneficial owners, 
information on source of funds and an understanding of the purpose and nature of the business relationship with 
the bank. 


The Business Areas' mappings have been cross checked against lists from another IT-system (which is held for 
tax-reporting purposes). This cross check confirms the Business Areas’ compilations of the customers in Sweden 
and the branches. However, further investigation is needed in the Baltics to secure that a complete picture of the 
situation can be presented. 


3. Actions going forward 


4. Appendices (optional reading) 


Situation in BA Swedish Banking (self-assessment) 
Situation in ВА LC&I (self-assessment) 

Situation in BA Baltic Banking (self-assessment) 
The Group's own dealings 


oom» 


1 Nota bene: the definition of "offshore" is not officially clarified and can be debated. 


© Swedbank 
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Appendix B 


Prepared for: Bjórn Meltzer, Viveka Strangert 


Report on Panama-papers mapping in LC&I 


Prepared by: Robert Schónbeck, Head of LC&I AML 
Office 


Introduction 


Large Corporates & Institutions (LC&I) is Swedbank's business area dedicated large corporations and financial institutions. 
Our client base is geographically diversified, including complex corporate structures spanning over a multitude of 
jurisdictions. Our product offering is a comprehensive portfolio of GTS and Markets products and is tailored to the needs of 
this client base but is also largely available to retail clients in Swedish Banking, Baltic Banking as well as private individuals in 


Private Banking. 


In response to the so called Panama Papers recently made public, LC&I has mapped our clients and transactions with the 
objective to uncover any connection we or our clients may have had with the law firm Mossack Fonseca in Panama. This 
report covers the areas of Large Corporates, Financial Institutions, all branches (incl the rep office in Johannesburg), CRM 
Retail, Trade Finance, Cash Management, International Cash Management, Securities Services, Transaction Banking, 


Investment Banking, and LC&I Legal. 
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Do you in your BA have customers with any other type of “shady business? 


3. If you find any customers that have a type of business/activity that you do not accept, what is your plan to get rid 
of them? 


4. Does your business area provide any tax advice tht could recommend non-acceptable tax evasion? 


What activities will you do to safeguard that no unwanted business/activity is conducted by customers in your BA? 


Customers with offshore engagements, FI 2019-09-04 , 2019-09-10 16:10 diarienr: 9000-K822-19 


6. If you feel you need more time to get the full picture of the situation, what actions are you doing to achieve that 
and when will you be finished? 


7. Other relevant information on the matter. 
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Appendix C 
Summary about Swedbank BA Baltic Banking (Estonia, Latvia, Lithuania) 


1. Do you in your BA have any customers with any type of relation with Mossack Fonseca 
(agreements, payments etc.)? Please specify number of customers and type of activity. 


ESTONIA: 


There are 28 customers (see Appendix 1) from 15 client groups who have used Mossack Fonseca as their 
registered agent in founding and managing an off-shore company. Ultimate beneficiaries of all these 
customers have non-Estonian background. The largest number (13) of Mossack Fonseca related 
companies are related with a client group сәһес ЕШ @ 9: one of the biggest coal producers in Russia 
having also a coal terminal in Tallinn. Considering the total number of companies in this Group (nearly 
200), Mossack Fonseca related entities make only a minor part of the whole Group. In all of these cases 


Swedbank has not had any kind of special direct relationship with Mossack Fonseca, the direct 
counterparty has always been the client itself. 


LATVIA: 


LITHUANIA: 


2. Do you in your BA have customers with any other type of “shady business”, e.g. shell companies 
in offshore jurisdictions? If yes, please provide information on if you have judged the 
arrangement acceptable and on what ground. 


ESTONIA: 
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LATVIA: 


LITHUANIA: 
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3. Ifyou find any customers that have a type of business/ activity that you do not accept - what is 
your plan to get rid of them? Can you estimate a time frame for that? What activities will you do 
to safeguard that no unwanted business/ activity is conducted by customers in your BA? 


ESTONIA: 


LATVIA: 


LITHUANIA: 


4. Does your business area provide any tax advice that could recommend nonacceptable tax 
evasion? 


ESTONIA, LATVIA, LITHUANIA: 
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5. Ifyou feel уои need more time to get the full picture of the situation — what actions are you doing 
to achieve that and when will you be finished? 


ESTONIA: 


LATVIA: 


LITHUANIA: 
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Appendix 1. Swedbank Estonia's clients with Mossack Fonseca link 


ЕЛ 
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Appendix D 


Swedbank Group's own dealings in offshore jurisdictions 


Investment 
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Sandén Ann-Christin 


Från: Christina Claesson <christina.claesson@fi.se> 

Skickat: onsdag den 18 september 2019 12:28 

Till: Sandén Ann-Christin 

Kopia: Alexandra Kettis; Langrot Thomas; Sandman Björn; Per Håkansson 
Ämne: SV: Re: Möte? 

Bifogade filer: Q1 2016 pwd.docx 


Hej Ann-Christin, 

Tack för att du och dina kollegor tog er tid att träffa oss tidigare idag. 

Jag ser att vi (inom ramen för den löpande tillsynen) fått in kvartalsrapporten för Q1 2016 som du efterfrågade. 
Däremot kan jag inte se att vi på motsvarande sätt fått in de två bilagor som refereras till i Q2-rapporten för 2016 
och som jag tror du också efterfrågade. Jag får be Alexandra såsom undersökningsledare att kontrollera om vi skulle 
ha tagit in de bilagorna inom ramen för undersökningen. 

Jag bifogar i a f kvartalsrapporten för Q1 2016. Den är lösenordskyddad och jag kommer skicka lösen separat till dig. 


Mvh, 


Christina 


Från: Sandén Ann-Christin <Ann-Christin.Sanden@ekobrottsmyndigheten.se> 
Skickat: den 12 september 2019 15:09 

Till: Christina Claesson <christina.claesson@fi.se> 

Ämne: SV: Re: Möte? 


Ja tack, det blir perfekt. 


Mvh 
Ann-Christin 


Från: Christina Claesson <christina.claesson Qfi.se> 
Skickat: torsdag den 12 september 2019 15:05 
Till: Sandén Ann-Christin <Ann-Christin.Sanden@ekobrottsmyndigheten.se> 


Kopia: Sandman Björn <Bjorn.Sandman@ekobrottsmyndigheten.se>; Langrot Thomas 


<Thomas.Langrot@ekobrottsmyndigheten.se> 
Ämne: SV: Re: Möte? 


Toppen - da ses vi hos oss 08:45 den 18/9. 
Ska jag skicka lösen till dig Ann-Christin? 
Mvh 


Christina 


Från: Sandén Ann-Christin <Ann-Christin.Sanden@ekobrottsmyndigheten.se> 
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Datum: 12 september 2019 14:59:16 CEST 
Till: Christina Claesson <christina.claesson@fi.se> 
Kopia: Sandman Bjérn <Bjorn.Sandman@ekobrottsmyndigheten.se>, Langrot Thomas 


<Thomas.Langrot@ekobrottsmyndigheten.se> 
Ämne: SV: Re: Möte? 


Hej igen, 
Har stämt av med Thomas och Björn och vi kan vara hos er kl 08.45. 
Tack för rapporten. 


Mvh 
Ann-Christin 


Fran: Christina Claesson <christina.claesson@fi.se> 

Skickat: torsdag den 12 september 2019 14:01 

Till: Sandén Ann-Christin <Ann-Christin.Sanden@ekobrottsmyndigheten.se> 

Kopia: Sandman Björn <Bjorn.Sandman@ekobrottsmyndigheten.se>; Langrot Thomas 
<Thomas.Langrot@ekobrottsmyndigheten.se> 

Ämne: SV: Re: Möte? 


Hej Ann-Christin, 


Tack för snabbt svar. Den 18 september passar oss bra men en av oss behöver gå till ett annat möte senast 09:45 sa 
jag undrar om ni kan tänka er att ses 08:45; eller t о m 08:30? Om inte, sa föreslår jag att vi träffas КІ 09:00. 


Jag återkommer om rapporten. 
Mvh 


Christina 


Fran: Sandén Ann-Christin <Ann-Christin.Sanden@ekobrottsmyndigheten.se> 
Skickat: den 12 september 2019 12:25 

Till: Christina Claesson <christina.claesson@fi.se> 

Kopia: Sandman Björn <Bjorn.Sandman@ekobrottsmyndigheten.se>; Langrot Thomas 


<Thomas.Langrot@ekobrottsmyndigheten.se> 
Ämne: SV: Re: Möte? 


Hej Christina, 

Vi har fått uppdraget av Thomas att återkomma till dig med möjligt datum för ett möte med er. Vårt förslag pa ett 
möte blir den 18 september, hoppas det är ett datum som även passar er. 

Vi kan fran klockan 09.00 och ser gärna att mötet är hos er. 


Vi önskar ta del av en rapport fran Swedbank som heter "Compliance Report Q2" för 2016 med bilagor samt en 
förteckning över andra rapporter som ni fått under första halvåret 2016. 


Med vänlig hälsning 
Ann-Christin Sandén 
Utredare/kriminalinspektör 
Finansmarknadskammaren 
Mobil 0733-31 54 46 


Från: Langrot Thomas 
Skickat: torsdag den 12 september 2019 10:42 


Till: Sandén Ann-Christin <Ann-Christin.sanden@ekobrottsmyndigheten.se>; Sandman Björn 
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<Bjorn.Sandman@ekobrottsmyndigheten.se> 


Ämne: Fwd: Re: Möte? 


Skickat fran Workspace ONE Boxer 


Fran: Langrot Thomas <Thomas.Langrot@ekobrottsmyndigheten.se> 
Datum: 12 september 2019 09:57:35 CEST 

Ämne: Re: Möte? 

Till: Christina Claesson <christina.claesson@fi.se> 


Hej Christina. Återkommer under dagen. 


Skickat från Workspace ONE Boxer 


Den 12 september 2019 09:04:25 CEST Christina Claesson <christina.claesson@fi.se> skrev: 


Hej Thomas, 


Vi pratade ju tidigare i veckan om att eventuellt ordna ett möte mellan dig/ditt team 
och representanter för vår undersökning. Jag skulle gärna vilja boka ett sådant möte 
och helst så snart det går. Du nämnde att ni är väldigt upptagna i närtid och jag 
tänkte därför att det kanske är bäst att vi börjar med att ni ger några tids-förslag för 
ett möte? Lite beroende på tidpunkt kan vi nog också vara flexibla var mötet sker - 
hos er eller hos oss. 


Från vår sida skulle det i s f vara Per Håkansson (Chefsjurist), Alexandra Kettis 
(Finansinspektör och undersökningsledare), samt jag själv som deltar i ett sådant 
möte. 


Jättetacksam om du kan återkomma om detta. 
Mvh, 


Christina 


CHRISTINA CLAESSON 
Rådgivare/ Senior Advisor 
Tillsyn stora banker/ Large Banks Supervision 


Finansinspektionen 

Box 7821, SE-103 97 Stockholm, Sweden 
Brunnsgatan 3 

Tel +46 8 408 980 00. Dir +46 8 408 982 53 
Fax +46 8 24 13 35 
christina.claesson(Qfi.se 


www.fi.se 
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Prepared for: the Board of Directors 


Compliance Report 


Q1 2016 


Highlights 


e AML/ CTF: Deficiencies in risk assessment, КҮС processes, screening & transaction monitoring within 
Baltic Banking. 


• Internal governance: Deficiencies in suitability assessment of key function holders. 


Please note that regular monitoring activities carried out according to the approved Compliance Plan will not be 
included in this report. A register of performed monitoring activities is kept by Compliance and available at request. 


Regulatory development is reported іп a separate report twice a year (Q1 and Q3). 
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Swedbank @ 
1. New Key Compliance issues and recommended 
actions 


1.1 AML/ CTF 


1.1.1 Insufficient AML Risk Assessments on country level 


BA/GP/GF 
Baltic Banking 


Reported 
Q1 2016 


Issue 

The three Baltic countries lack sufficient and documented AML Risk Assessments on country level. 
There are risk assessments in place to some extent but these mainly cover customer segmentation 
rather than the required total scope (customers, products, channels, geographies and transactions). The 
AML Risk Assessments provide the basis for risk management including setting relevant КҮС 
processes, transaction monitoring, follow-up etc., and therefore need to be prioritised. 


Consequences 

The business area is not compliant with internal and external regulations regarding AML Risk 
Assessments. By not having a relevant risk assessment in place, Baltic Banking may fail to assess 
relevant risks and ultimately increase the risk for being used for money laundering or terrorist financing 
purposes. Ultimately there is a risk for regulatory sanctions, negative impact on Swedbank's funding, 
impaired correspondent banking relationships and bad/non-compliant business decisions. In addition the 
lack of relevant AML Risk Assessments might lead to inefficient risk management as AML-related 
processes might not be set up according to a risk based approach. 


Actions 


Compliance support 
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Insufficient КҮС processes 


BA/GP/GF 
Baltic Banking 


Reported 
Q1 2016 


Issue 

Тһе KYC processes іп all three countries need to be clarified in terms of level of customer due diligence, 
KYC information documentation and storage, follow-up etc. KYC data must be easily retrievable and 
part of transaction monitoring parameters. The processes need to be based on each country's AML Risk 
Assessment. All countries currently use customer declaration forms for KYC that are similar, but with 
more uniform templates and processes efficiency gains could probably be achieved, as similar 
information is necessary throughout the business. Moreover, it is not clear if and how the KYC is 
validated and followed-up in the business to ensure that all customers have relevant and updated KYC. 
Therefore there is a need to scrutinize and probably improve such a process, and implement it based 
on the AML Risk Assessment. In addition, in order to meet the updated LV FSA regulation (in force since 
December 2015) on enhanced customer due diligence requiring implementation of customer AML 
statistical risk scoring, a proper action plan should be set up to implement these new requirements. It 
should be also evaluated if some processes related to AML risk handling can be aligned on the Baltic 
level. 


Consequences 

By not having a relevant and documented KYC on all clients in Baltic Banking, the business area is not 
fully compliant with internal and external regulations, and consequently there is a risk of sanction from 
the supervisory authorities. Additionally, the bank might not detect and act upon all suspicious money 
laundering and financing of terrorism that flows through the bank's systems. 


Actions 


Compliance support 
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1.1.3 


Swedbank @ 


Insufficient sanction screening of transactions, and sanction and PEP screening of 
customers 


BA/GP/GF 
Baltic Banking 


Reported 
Q1 2016 


Issue 


Transaction Screening 
The three countries currently use an in-house solution for screening of international payments. All 


possible hits are forwarded for further manual analysis to the local AML teams. However, the in-house 
solution does not have the fuzzy matching functionality’ meaning that there is a risk to miss the payments 
containing sanctioned items in case of deviations from exact matches. Moreover, domestic payments 
and SWIFT messages must be screened in relevant parts. 


Customer Base Screening 
Online screening of new customers and beneficial owners must be implemented to avoid onboarding of 


customers or beneficial owners, which are on the sanction lists. Also individuals that are politically 
exposed persons (PEP) must be identified so they can be treated accordingly. It is not sufficient to 
screen individuals after they are on-boarded, as is the case today. 


On-going activities 
Presently, several AML projects are working to close the identified gaps and they are highly prioritized 
due to the urgency. 


Consequences 

An insufficient sanction screening risks that the Group has a business relationship with a sanctioned 
party. A breach of a legally-binding financial sanction (EU) would have severe impact on the Group and 
could ultimately risk the banks license and personal imprisonment of the CEO. A breach of a non-egally 
binding financial sanction (OFAC) could negatively impact the Group's relations with international 
investors and correspondent banks, leading to reputational risk, funding issues and the possibility to 
provide customers with international payment products. 


Actions 


Compliance support 


1 Meaning that miss-spelled words, words that are written together without space, etc. are not captured in the system and do 
not create a hit. 


INTERNAL AND CONFIDENTIAL Page 4 of 12 


[ Compliance Report Q1 2016 fr FI 2019-09-18. , 2019-09-18 13:46 diarienr: 9000-К822-19 


32 


1.2 
1.2.1 


1.2.1.1 


Swedbank@ 


Insufficient transaction monitoring 


BA/GP/GF 
Baltic Banking 


Reported 
Q1 2016 


Issue 

The three countries currently use different tools for transaction monitoring, all of which are more or less 
manual. There is a need for a system-based transaction monitoring system with relevant scenarios to 
detect money laundering and terrorist financing based on each country's AML Risk Assessment and in 
line with both local regulation and Group minimum requirements. This means that the transaction 
monitoring should cover both the mandatory reporting according to local FSA requirements as well as 
risk based transaction monitoring daily, based on the risks identified in the AML Risk Assessments. 


Consequences 


Transaction Monitoring 
An inefficient transaction monitoring and non-compliance with relevant regulations might lead to 


Swedbank being used for money laundering or terrorist financing purposes, regulatory sanctions, 
damage on the Swedbank brand and an insufficient reporting to the FIU. 


Actions 


Compliance support 


Internal Governance 


Deficiencies in suitability assessment of key function holders 


Lack of policy 


ВА/ GP/ GF 
Group HR 


Reported 
Q1 2016 


Issue 

In accordance with the EBA guidelines on assessment of the suitability of key function holders, the 
Bank shall have a policy in place for assessing the suitability of key function holders that sets out at 
least the positions for which a suitability assessment is required, the individuals or function responsible 
for performing the suitability assessment, and the criteria for reputation and experience to be assessed 
for the specific position. In addition, the Guidelines on Internal Governance require that the 
management body should have a policy in place for selecting, monitoring and planning the succession 
of key function holders. As demonstrated by the monitoring performed by the Compliance Function, 
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Swedbank @ 


the Bank tacks a policy for assessing the suitability of key functions holders and a policy on the 
nomination and succession of individuals with key functions. 


Consequences 

The lack of a policy entails that the Bank is non-compliant with the EBA guidelines and also the 
Guidelines on Internal Governance. The non-compliance could lead to a risk that the Bank has key 
function holders that are not suitable for their positions, i.e. they could lack experience for their positions 
or not be of good repute. 


Actions 


Compliance support 


1.2.1.2 Governance and internal control 


ВА/ GP/ GF 
Group HR 


Reported 
Q1 2016 


Issue 

Chapter 2, Section 1 of the S-FSA Regulatory Code on Governance, Risk Management and Control, 
FFFS 2014:1, states, among other things, that a bank shall ensure that its organisational structure is 
transparent with a clear allocation of functions and areas of responsibilities ensuring sound and efficient 
governance. The EBA Guidelines on assessment of the suitability of key function holders set out the 
process, criteria and minimum requirements for assessing the suitability of the Bank's key function 
holders which should be included in the Bank's policy for assessing the suitability of key function 
holders. As demonstrated by the monitoring performed by the Compliance Function, the Bank has 
inadequate governance arrangements and lack of an internal control structure within Group HR in 
relation to suitability assessments of key function holders. The internal guidelines, provided by HR, are 
insufficient and not comprehensive. 


Consequences 

The inadequate governance arrangements and lack of internal control structure in the process for 
suitability assessments of key function holders do not meet the requirements set out in Chapter 2, 
section 1 in FFFS 2014:1, nor the EBA Guidelines. The non-compliance has led to the non-execution 
of suitability assessments of key function holders and could lead to the risk that the Bank has key 
function holders that are not suitable for their positions, i.e. they could lack experience for their positions 
or not be of good repute. 


Responsible person 
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Compliance support 
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2. Follow-up Compliance issues 
a E Е] 


All parts in this section have been previously reported. 

Headings 
AML/ СТЕ: КҮС routines and processes, PEP, Financial sanctions. 
Customer protection: Banking secrecy, fund management information, 
documentation of investment advice. 


Internal governance: Management of top level exectives agreements with the 
Bank, internal control structure for outsourced services. 


2.1 AML/ CTF 


2.1.1 Insufficient KYC routines and processes 


BA/ GP/ GF 
Swedish Banking 


Reported 
Q1 2014 


Issue 


Actions 
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Compliance support 


2.2 Internal governance 


Page 10 of 12 


INTERNAL AND CONFIDENTIAL 


‘Compliance Report Q1 2016 fr FI 2019-09-18. , 2019-09-18 13:46 diarienr: 9000-K822-19 


3. Other compliance matters 
ENN ee ee n — — == “ass 


Headings 
Compliance - general 


Staff situation 
Other matters 


3.1 Compliance - general 
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Swedbank @ 


3.2 Staff situation 


3.3 Other matters 


4. Appendices 
SE eee E] 
e Follow-up on customers with offshore structures etc. (Appendix 1) 
e Regulatory Watch report (Appendix 2) 


e AML Program (Appendix 3), optional reading 
e Regulatory contacts, (Appendix 4), optional reading 
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ERLING GRIMSTAD 


Phone: +47 997 97 542 + email: egQgovernance.no 
wwwW.governance.na 


DRAFT MEMO 


Prepared for 


Swedbank AB 


9 June 2017 


ADDITIONAL OBSERVATIONS FROM AML INVESTIGATION – 
SWEDBANK ESTONIA 


Disclaimer 

This memo for Swedbank AB is made by Erling Grimstad, a Norwegian lawyer practicing from Advokatfirmaet Erling Grimstad AS (Norway) 
and member of the Norwegian Bar Association. The ability to engage in any activities on behalf of a client outside Norway is subject to 
statues and professional codes and court rules. Any legal advice or opinion rendered on laws or regulations outside Norway, should be 
consider not necessarily to be within my expertise. You should seek appropriate counsel for specific legal advice outside Norway, to 
understand your position and obligations in accordance with the national law. This report is strictly confidential and contain attorney — 
client privileged information solely prepared for Swedbank AB. 
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1. Swedbank Estonia — preliminary findings of high risk transactions and clients... 


2. Reputational and legal risks for Swedbank in the cases presented in this memo 


3. Cases of criminal investigation and potential high reputational risk ...................... een 
3.1. Use of proxies including the network of @ ШШШ. ....................................................... 
3.2 Hermitage Capital Management — the "Magnitsky case"... 
зз С 5 $5 65 à BM 
3.4 The Deutsche Bank Case.......................... u. u наи иннин 
3.5 Individuals and companies involved in the sale or transportation of weapons and arms..... 
3.6 Transactions with Ukrainian counterpqarties........................ eee eee enne nnn nennen 
3.7 The company ПИ с па illegal oiltrade................................................... 12 
3.8 ES O e 
3.9 The Moldova “Russian Laundromat” case ............. eese esses eene nennen enn nnne nennen 
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1. Swedbank Estonia — preliminary findings of high risk 
transactions and clients 


The purpose of this memo is to give Swedbank (the “Bank”) additional information 
pertaining to findings of certain high risk transactions and high risk clients, including other 
than the Focus Clients. Our intention is also to make the management aware of the potential 
risks involved and advise on how to mitigate those risks. 


During the AML investigation we found information of the Bank’s possible involvement in 
publically known criminal investigations and proceedings. The Bank should be aware of 
indications of possible criminal activities and certain high risk clients. While some of the 
transactions go years back in time, they might still lead to risk for the Bank today: Media 
attention, inquieries from corresponding banks and from epmployees as well as from 
individuals and entities claiming compensation. There is an inherent risk of the Bank, directly 
or indirectly, being subjected to criminal investigations related to the Bank’s role in providing 
and facilitating services for certain high risk clients. Given the nature of the transactions and 
persons in question, there is also a considerable ongoing reputational risk for the Bank. 


This memo is in no way exhaustive. The memo is made on the request of the recipients. 
Further investigation into the matters described in this memo might reveal additional 
information confirming or rejecting any risks for the Bank. 


The indications of potential money laundering related to the Focus Clients will be described 
in the final AML Report in June 2017. 


We also identified requests for the transfers of substantial amounts in USD and EUR from 
Focus Client without proper justification of the origin of funds or nature of business. We also 
found some cases referred to as “overnight deposits”. These examples will be described in 
the final AML Report. 


It is important to point out that we did not look to identify links to the below cases at the 
offset of our investigation, and that we had no prior information of those cases beyond 
publicly available information. However, based on information that transpired during our 
investigation of the Focus Clients we identified indications of potential connections to the 
matters described below. Further inquiries into those matters are made based on open 
sources and searches, as well as publicly available databases. 


2. Reputational and legal risks for Swedbank in the cases 
presented in this memo 

Most of the cases presented in this memo represent serious reputational risk for the Bank if 
the information become publicly known. Several of the cases presented may potentially lead 
to criminal investigation of the Bank and/or employees. Enhanced investigation into the links 


and information found, may reveal more enhanced description of the real risks for the Bank. 


One of the most surprising findings to us has been the volume of entities and individuals 
accepted as clients by Swedbank Estonia without any adequate identification of the real 
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owners, the origin of funds or the purpose and intended nature of business. Lack of such 
information makes it almost impossible for the Bank to conduct any proper and risk based 
monitoring or scrutiny of transactions. This practice seems to have taken place for years and 
have made the Bank vulnerable for being used by clients for criminal activity. There is severe 
risk for criminal investigation of the Bank and employees on the basis of suspicion of money 
laundering. 


There is also a risk of civil claims from individuals, entities and governmental institutions 
claiming compensations for financial losses due to the Bank's role in transactions for clients 
committing fraudulent schemes, embezzlement or other criminal activities. As an example 
there are ongoing efforts to trace and secure assets from criminal origin in the case of 
Hermitage Capital Fund (see case presented in chapter 4.2 in this memo). 


Several findings described go years back in time. Even for the findings in the dataset that 
goes back to 2009, there is a present legal risk for the Bank being investigated by authorities 
or claimed for compensation from external parties. There is also a risk for scrutiny from 
authorities investigating tax evasion, unexplained wealth and money laundering.’ 


3. Cases of criminal investigation and potential high 
reputational risk 


| 
| 


1 An example is the UK Criminal Finances Act of 2017: 
http://www egislation.gov.uk/ukpga/2017/22/contents/enacted/data.htm 


2 https://www. youtube.com c w 


3 https://www.reportingproject. ne Till 


4 http://rubakhin.org/? 


5 the globalinitiative.net website 
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2 Hermitage Capital Management – the “Magnitsky case” 


| 
| 
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4 Тһе Deutsche Bank Case 
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Rapport Signerat av 


Myndighet 
Ekobrottsmyndighe20 7-06-28 Observations Swedbank Estonia Managemerñisnerat datum 


Enhet 


Diarienr 


Stockholm FMK 9000-K822-19 
Orglnalhandlingens fürvaringsplats Datum Tid 
2021-01-13 12:38 
Involverad personal = Funktion 
Björn Sandman Uppgiftslämnare 
Berättelse 


2017-06-28 Observations Swedbank Estonia Management Final 
Från beslag 2019-9000-BG294-1 Mejlbeslag husrannsakan Swedbank 
Ligger som bilaga i e-post Erling Grimstad skickat 2019-03-13 till Håkan Bengtsson. 


Av mejlslingan framgår det att den tidigare skickats den 28 juni 2017, 
till Jan Fecko och Johan Rosen Swedbank. 
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From: Erling Grimstad <eg@governance.no> 

Sent: 2019-03-13 21:22:52 +0000 

To: Håkan Bengtsson <hakan.bengtssonQswedbank.com> 

Subject: FW: FW: Final Report [KA-Active.FID673373] 

Attachments: Observations Swedbank Estonia ManagementFinal (12554586_1).PDF 


Erling Grimstad 

Advokatflrmaet Erling Grimstad AS 

Gaustadalléen 21, 0349 Oslo 

T: +47 997 97 542 

E-mail: eg@governance.no 

www.governance.no | www,personvernraddiveren,no 
Opplæring i anti-hvltvaskIng: www.amlapp.no 


Din digitale personvernrádgiver (GDPR): https://www.personvernradgiveren,no/chatbot 


Denne e-posten med tilharende vedlegg er kun for adressaten som er navngitt ovenfor og kan inneholde advokat - klient informasjon som kun er ment for mottakeren. E-post med tilhørende 
dokumenter kan inneholde opplysninger som er undergitt taushetsplikt, Dersom mottaker har mottatt e-posten ved en feil, bes mattaker straks gi beskjed per e-post eller telefon og samtidig 
slette e-posten og makulere eventuelle utskrifter eller kopier av denne. 


Please note that thls message may contain confldentlal information, 


If you have received this message by mistake, please inform the sender of the mistake by sending a reply, then delete the message from your system without making, distributing or retaining any 
copies of it, Be aware that the recipient opens this message at his or her own risk, We assume no responsibility for any loss or damage arising from the receipt or use of this message, 


Fra: Tormod Tingstad <toti@kammeradvokaten.dk> 

Dato: onsdag 28. juni 2017 11:41 

Til: Jan Fecko <jan.fecko@swedbank.com>, Johan Rosen <johan.rosen@swedbank.se> 

Kopi: "hakan.bengtssonGswedbank.com" <hakan.bengtsson@swedbank.com>, Andreas Hobbelin 
<andreas.hobbelin@swedbank.no>, Erling Grimstad <eg@governance.no> 

Emne: Final Report [KA-Active.FID673373] 


Dear Gents, 

For the sake of good order, please find our report on the Estonian management enclosed in its final form. 

Apart from tidying up a few typos, we have included the customary disclaimer regarding the application of foreign law. 

I understand this part of the assignment is now brought to a close. However, please do not hesitate to call on us should you require any further assistance now or in the future. 
1 thank you for the good cooperation and interesting work, and wish you all a well-deserved summer break. 


Yours sincerely 


Tormod Tingstad 
Associate Partner [0] 


Direct +45 50 95 08 85 
toll 


Kammeradvokaten 
Law Firm Poul Schmith 
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Message Headers: Received: from SRV62317.fspa.myntet.se (10.8.31.63) by SRV62318.fspa.myntet.se 
(10.8.33.61) with Microsoft SMTP Server (TLS) id 15.0.1367.3 via Mailbox 
Transport; Wed, 13 Mar 2019 22:23:01 +0100 
Received: from SRV62317.fspa.myntet.se (10.8.31.63) Бу SRV62317.fspa.myntet.se 
(10.8.31.63) with Microsoft SMTP Server (TLS) id 15.0.1367.3; Wed, 13 Mar 
2019 22:23:00 +0100 
Received: from mail5out.sbcore.net (10.8.31.9) by SRV62317.fspa.myntet.se 
(10.8.31.63) with Microsoft SMTP Server id 15.0.1367.3 via Frontend 
Transport; Wed, 13 Mar 2019 22:23:00 +0100 

X-IronPort-AV: E=Sophos;i="5.58,475,1544482800"; 
d="pdf'?png'150?scan'150,208,217,150";a="103998398" 
X-Amp-Result: UNKNOWN 
X-Amp-Original-Verdict: FILE UNKNOWN 
Received: from unknown (HELO sto03-pmg003.swedbank.net) ([10.8.35.6]) 
by mall5in.sbcore.net with ESMTP; 13 Mar 2019 22:23:00 +0100 
Received: from localhost (localhost [127.0.0.1]) 
by sto03-pmg003.swedbank.net (Postfix) with ESMTP id 44KPvVQ5wWDz34Zq5 
for <hakan.bengtsson@swedbank.com>; Wed, 13 Mar 2019 22:22:58 +0100 (CET) 
X-MTA-CheckPoint: (5C8974B2-0-CD64630A-5CF5) 
Received: from maillin.swedbank,se (unknown [10.8.35.9]) 
by sto03-pmg003.swedbank.net (Postfix) with ESMTP id 44KPvQ5Gmsz34Zpv 
for <hakan.bengtsson@swedbank.com>; Wed, 13 Mar 2019 22:22:58 +0100 (CET) 
Recelved-SPF: None (mail1.swedbank.se: no sender authenticity 
information available from domain of eg@governance.no) 
Identity pra; client-ip=40.107.14.70; 
receiver=maili.swedbank.se; envelope-from="eg@governance.no",; 
x-sender="eg@governance.no"; x-conformance-sidf compatible 
Recelved-SPF: Pass (mall1.swedbank.se: domain of eg@governance.no 
designates 40.107.14.70 as permitted sender) 
identity=mailfrom; client-ip=40.107.14.70; 
receiver=malli.swedbank.se; envelope-from="eg@governance.no"; 
x-sender="eg@governance.no"; x-conformance=sidf_compatible; 
x-record-type-"v-spf1"; x-record-text="v=spf1 
ip4:157.56.112.0/24 ip4:207.46.51.64/26 1р4:64.4.22.64/26 
ір4:40.92.0.0/15 ір4:40.107.0.0/16 ір4:134.170.140.0/24 
include:spfb.protection.outlook.com ірб:2001:489а:2202::/48 
-all" 
Received-SPF: Pass (maill.swedbank.se: domain of 
postmaster@EURO1-VE1-obe.outbound.protection.outlook.com 
designates 40.107.14.70 as permitted sender) identity-helo; 
сіепі-ір-40.107.14.70; receiver=mail1.swedbank.se; 
envelope-from="eg@governance.no"; 
x-sender="postmaster GEURO1-VE1-obe.outbound.protection.outlook.corn"; 
x-conformance-sidf, compatible; x-record-type="v=spfi"; 
x-record-text="v=spf1 ip4:157.56.112.0/24 ip4:207.46.51.64/26 
ip4:64.4.22.64/26 ip4:40.92.0.0/15 ip4:40.107.0.0/16 
1р4:134,170.140.0/24 include:spfb.protection.outlook.com 
ірб:2001:489а:2202::/48 -all" 
Authentication-Results: maili.swedbank.se; spf=None smtp.pra=eg@governance.no; spf=Pass smtp.mailfrom=eg@governan 
IronPort-PHdr: 9a23:gjkAbx94WIUGN/9uRHKK80MuRw1ilqv9OhMc9p 
sgje4SK/a9qs2xdEWK/4- 5kyUTJVN --GtaEMgL/MvqTpSWEMpoyMtHKkSfZAfMn 
1NhZAbhQghBsGKEOz- N--LjY209GsFDXOVi5HaiLQ5eH8OtLOaHuXC24DUOHQ 
4mcAVyOOnvHIfUhMnyOefhnv--bY1Bmnj24M597 MBjklhjbtMQdndlHJ70qwx 
TES1pkKc9Rw39lI07Wowfk65WV 3btOthpdoekg8MgSYeDfROEVXbdYBTIpPi 
UO6cvnuAPqYSCP63AfAQBO2hBIVg/PyS65earuvgT/7s9CwAu1IIrZdpw5QT 
WYyKtoCyXOgxcNCi9-t wkHyiekl 38c56BjOqhdlnrfqfYCIGNBVVYXYPoMwHW 
EGX--dS5C290Da2MTpUOMMOmGboAjdSiiFowlhmcXy69XrvOlgZkvCLyz64Ui/ 
olLQJH2FQ/BY9TiVmJ7-4-j3Cagee806zLXo3A/pf/AL-- DL679TDVA8jmralYY 
prQ8P48BgrBh--UpXK9tqamGhKekeQBqU624bN/ebOFzGwjrTNJhySt5s0V12Z 
mO14M5zELW2wWNIkKo2OvbkHROzcZulCpxWryaAK85sT9g/R3090CBh0e5c48 
ySYTQKxZI7xhXWd/2Adc2y7wn-- UPqKe2skindsebbmwQ2t/ESqw-rv/ENK5gx 
SRtiQQtN7KuzgWOgDLrNCdQ65w8W-ru3iiCzQba7OpJZOYzxuLAMSBO-t rcrjd 
IItFjbWCr/mUH4lgiTIOgrOuev9en9ZLzgrZLaMYgnwhrmPPEWKk9ekSf89Lh 
BIX2Wf/rGk06b/--ETIXLhQptALqPGA92a73fIEcrKP/BBJJ2IE--7Rr5Fy2hzN 
kTgXgAKhRCZQ6Dil/qfVvrJJaOwAfS--hgG0mSxwj7DdP7LnC4nQNHWLjrr7fL 
h85kIdgAo+xNxS/dRVXSkMOvbyXED+rt3dFQMwP0qzxePmA896zYQQRSSEBa 
rAavHovFSF5/wiL6y3XKFP522vDf8j6rauiHY4nQZbZrak0ZEebnP-rBfkO0a0 
OeKWHhhNsMCy8DoxY + Qer2iVaDTS82BT76XqQy4Ss-FAZ6nCoGLT56kgbil1i 
O2VpNMYWUOBIeJGHbUPAKKE/oDQC2VPMJ7IDUCXrXnTYhasHPm/A72xrx7L/ 
bFrzUCvMGr39x06uvPOBAqoGAsSZ3FjCfUEycrxjBUXd *xq10rE1jx03W 1K 
F5h6UeDsNe6/IAVARSLpOPh+F8Fd32XRrMO9mTT1PZCNipKT42UN8rxdYlaE 
S7HdLo3XWhI2K6RqQYkbCGHsl--/6300H/vKtx7wnDN2e8niBN1CtsKPmqgiK 
llBgHVDIOciESVmZGhcqEE 1TLM/mOOIDDchkxTXQ9uXKmAZKgxOXKK/-t zw/V 
IKD7qnCLB+dBBexMKII61ILMbk3x1KQ/LqOdKWZGz5ImIYChGWy6mKZYzhdi 
-?us-ascii?q? Mb20C/QAAInhsS8nCP 
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Swedbank 
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1. Summary 


Swedbank in Estonia (the Bank) has been downsizing its high risk non-resident 
(HRNR) business over the past year — a work that triggered an examination of 
one of its largest customer Groups — Carbo One. A Project (CLEAR) was formed 
to investigate for any possible AML violations and possible wrongdoings by 
employees during the business relationship with Carbo One - going back several 
years. During this investigation more affiliations were identified and the scope was 
extended to a virtual group of customers – the "Focus Group". 


The client relationship with the Focus Group dates back to 2002-2003, when the 
then head of trade finance of Hansabank -SD - left the Bank to work 
full time for one of the affiliated companies, НВ АС. The Focus Group of 
companies is in turn controlled by Russian citizens | www (ID 
(ЕВ and . 


Up until the off boarding in 2017 of customers belonging to the Focus Group no 
transaction suggestive of money laundering was stopped or reported to FIU albeit 
the presence of e.g. questionable loan agreements and invoices with or between 
the companies in the Focus Group. The investigation found no evidence of any 
proper investigation of suspicious transactions pertaining to the Focus Group in 
the reviewed period from 2012 to February 2017. 


The due diligence of clients belonging to Focus Group was inadequate and the 
Bank failed to obtain sufficient information about the clients and their business 
which should have led to the decision not to accept the clients. It cannot be 
excluded that the Focus Group may have used the Bank for money laundering 
purposes. Money laundering was made possible by giving the clients the 
opportunity to transfer large funds in different currency to bank accounts 


1 However it is not unlikely that the ultimate beneficiaries are other even more prominent Russians, most notabl 5 1] 
and 
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controlled by offshore entities, without fully understanding the real nature of 
business, the interests beyond transactions or properly questioning the source of 
funds. 


The investigation identified no indications or intelligence that employees have 
received remuneration from the Focus Group in exchange for the facilitation of the 
relationship with the Bank. Nor has the investigation identified evident external 
ties between employees or managers and the Focus Group beyond normal 
business relations. 


However, the management has collectively failed to act to protect the bank and to 
comply with the bank's legal obligations. The investigation concludes that the 
Senior management of the Bank has not fulfilled its express obligations in key 
areas of responsibility related to anti-money laundering nor has it promoted a 
culture of competence, transparency and trust in relation to AML obligations. The 
failure to comply has been ongoing throughout the whole period of review (2012 - 
2016). 


2. Background 


21 De-risking ће НЕМЕ? portfolio in Swedbank Estonia 


2.2 Conclusions from off-boarding 


? High Risk Non-Resident is defined as entity registered outside of the EU countries and Norway, excluding Malta, Cyprus, UK 
and Luxembourg plus 13 EU PSPs because of technical reasons 
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2.3 Accelerated off-boarding and enhanced monitoring resulted іп several 
reports to FIU 
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2.4 Lessons learned 


During the off boarding process HRNR clients were put under pressure to empty 
accounts and find new banking relationships. The underlying account contracts 
enabled Swedbank to close the business without any particular reason and with a 
grace period of two months. The accelerated closing of accounts in combination 
with the difficulties the clients experienced in opening accounts in other banks 
triggered behaviours such as loan agreements between Focus companies that 
likely raised more red flags and reports to FIU compared to ordinary business 
prerequisites. However, it is clear that these relationships should have raised 
more red flags and transaction refusal and/or suspicious transactions reports to 
FIU? in the past due to the many times low quality of underlying documents and 
unclear purposes of transactions or other high risk indicators. 


3. AML Investigation 


wo 


„1 The investigation 


од 


2 Focus Clients 


| 
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3.3 AML investigation into Focus clients 


3.3.4 Conclusions from AML investigation 

It cannot be excluded that the Focus Group may have used the Bank for money 
laundering purposes. The Bank made such transactions possible by giving the 
clients the opportunity to transfer large funds in different currency to bank 
accounts controlled by offshore entities, without fully understanding the real 
nature of business, the interests beyond transactions or questioning the source of 
funds. 


The lack of an effective and adequate AML programme including, but not limited 
to, monitoring of clients and transaction as well as proper governance and internal 
control and the high risk for involvement in facilitating money laundering for 
clients, increased the risk for the Bank. 


The overall finding from the AML investigation is the systematic weakness in our 
AML operation due to low AML competence and compliance culture. Deficiencies 
in the AML control framework are mainly identified in relation to the customer 
acceptance and the monitoring of transactions where several warning signs and 
indicators of money laundering appear to have been missed or neglected. 


3.3.2 Weak compliance culture 

There were no real signs found of a risk based approach to the AML processes 
and there were no explanations why employees did not comply with the AML 
policies and routines in practice. Management involved in the AML process for the 
Focus Group did not have a clear understanding of their role and the separate 
activities defined to be made by 1* line of defence (client management) and 2nd 
line of defence (compliance) in the Bank. This confusion and misunderstanding 
have led to lack of proper monitoring and oversight of the Bank's AML obligations. 


3.3.3 Ineffective monitoring 

The Bank monitored transactions for the Focus Group (and other clients) 
retroactively on weekly basis, followed up by asking the client additional 
questions. The client managers who presumably had the best knowledge of the 
clients and their businesses, was responsible for this weekly monitoring. The 
investigation, however, gives the impression that all these efforts were done more 
or less as a “tick in the box" exercise with no real understanding of the aim or the 
purpose of the AML requirements. 


Up and until the off boarding period in 2017 no transactions suggestive of money 
laundering was stopped and/or reported to FIU in accordance with mandatory 
AML laws. These include questionable loan agreements or invoices with or 
between companies in the Focus Group. The AML investigation found no proof of 
awareness of money laundering indicators or any evidence of any proper 
investigation of suspicious transactions for the Focus Group in the reviewed 
period from 2012 to February 2017. 
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3.3.4 Weak КҮС 

The due diligence of new clients was inadequate and the Bank failed to obtain 
sufficient information about the client and its business in several occasions. 
Clients refusal to provide sufficient and relevant information to the Bank should 
have led to the decision not to accept the client. 


There was only one employee, the former client manager, who could say if an 
entity was connected to the group of . He was apparently the 
only employee in the Bank who had the insight and knowledge to conduct proper 
monitoring of transaction. He did however not identify any suspicion of money 
laundering. 


3.4 Investigation of any possible wrongdoing by Swedbank Estonia 
employees 


3.4.1 Collective liability 

While the investigation have not found any criminal act purported by a specific 

member of the management of the bank the management has collectively, and to 

different degrees, failed to act to protect the bank and to comply with the bank's 

legal obligations. Senior management has not (real or perceived) adequately 

understood the risks associated with the Focus Group Clients and the 

investigation concludes that: 

• Senior management has not fulfilled its express obligations in key areas of 
responsibility related to anti-money laundering 

e Senior management has not promoted a culture of competence, transparency 
and trust in relation to AML obligations 

« Senior management's failure to comply has been ongoing throughout the 
whole period of review (2012 — 2016) 


3.4.3 Everyone involved was to some extent aware 
The entities set up by Focus Group in Cyprus were owned by ВУІ entities to hide 
the names of the real owners. 


On paper, there were no links between the entities and the ultimate beneficial 
owners. A vast majority of the companies had nomine shareholders (proxies and 
strawmen registered both officially and in the bank as beneficial owners). The 
links between entities and the group ЕЕЕ was based on oral 
information from contact persons of the Focus Group an interpretation of 
transactions; historical cash flow and counter parties. 


Several of the members of the management board in the Bank had knowledge of 
the Focus Group and their refusal to provide the Bank with needed documents, 
e.g. shareholder agreements, signed documents of ownership and proper 
documentation of links between the entities and alleged beneficial owners. 


According to a number of employees in the Bank as well as according to internal 
documents reviewed, the former Head of the Compliance department in Estonia, 
throughout the review period, was aware that the beneficial owners of the entities 
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of the companies within the Focus Group were поі documented іп the official 
documents. 


New entities were accepted as clients of the Focus Group without proper 
documentation and the Bank opened bank accounts even if there were no proof 
of the source of funds and the entity was represented by an individual operating 
on behalf of others. 


3.4.3 No evidence of personal gain 

The investigation has not identified any clear elements to suggest that employees 
or members of the management board lead lifestyles which are beyond their 
means. Similarly, the investigation identified no indications or intelligence that 
employees have received remuneration from the Focus Group in exchange for the 
facilitation of the relationship with Swedbank. Nor have the investigation identified 
evident external ties between employees and the Focus Group. 


However, the absence of outward indications of excessive wealth does not mean 
that individuals were not involved in wrongdoing. It simply means that in Estonia, 
and in Russia, their asset profile is in line with their income. 


During the investigation one individual of interest arose: ШШШ. 2 
Swedbank Estonia ОИ 
ПИ registered wealth does not appear to exceed his earnings, and the 
sampling review of И correspondence identified no indication that his 
interaction with the Focus Group was beyond what сап be expected of а sl 
HIN However, the investigation identified instant messaging communication 
ремеег ЕЕЕ and his colleague that indicates he had knowledge that certain 
transactions made by companies within the Focus Group were likely irregular. 
In discussing one transaction with a colleague, Said this transaction was 
“not the whitest of deals”, using a colloquialism indicating it was not transparent. 
In another communication, where it is not clear whether they are discussing a 
Focus Group company or another client, 8 Says to a colleague that one 
transaction received by an unspecified company was listed as being related to 
gas transportation services, and then left the same entity as “prepayment for 

"6 


stationary goods". described this transaction as "a tall fale". 


Client memorandums produced by ЕЕ in 2009 and 2016 suggest that he 
was familiar with the corporate structure of the focus group, its ultimate 
beneficiaries, the names of intermediaries and nominees and the manner in which 
focus group companies intended to move funds across the group by means of 
inter-company loans. 


° The Russian used in this context translates literally to mean ‘fairy tale’ 
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4. Contacts with regulators and 
authorities throughout the project 


4.1 Financial supervisory Authorities 


The project has during the off-boarding had contacts with relevant authorities and 
have had meeting with the Estonian FIU and FSA in order to explain the 
increased number of transactions reported as well as the reasons behind the 
reports and other circumstances related to the off-boarding and the way forward. 


5. Recommendations 


5.1 The way forward — no legacy business culture 


Based on the findings made during the de-risking and off-boarding period it is 
clear that Swedbank Estonia needs to ensure a stronger culture of AML 
compliance and business ethics. This entails a change of culture, risk awareness 
and knowledge within the different business units as well as other parts of the 
bank, empowering the Compliance staff with sufficient authority, knowledge and 
autonomy to follow up on AML compliance as well as facilitating in implementing 
the new AML program. Furthermore it entails that all three lines of defense are 


empowered to conduct their duties and understand their roles and responsibilities. 


Circumstances associated with legacy business culture needs to be flagged and 
questioned, including but not limited to: 

e Arrangements with asset-holding vehicles and proxies/nominee shareholders 
+ Тһе ownership by offshore entities and certain other entities such as LP 
entities in UK. 

Complex client structures 

Difficulties to confirm the business from open sources 

Payments received from unknown or un-associated third parties 

Close connections between businesses and the owner's private wealth 


AML training needs to be updated, tailored to responsibilities and executed for 
leaders, AML compliance staff, client managers and other relevant staff. There is 
also a need to ensure appropriate mechanisms for sharing information within the 
organization and for information sharing on Money Laundering Reporting Officer 
level as well as seeing to that there are sufficient technological, human resources 
and relevant competence to fulfil AML obligations. 
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5.2 Further actions proposed by the external AML Investigator based оп 
the findings from the AML investigation. 


5.2.1 Board of directors 

Effective AML risk management requires proper governance arrangement and the 
board of directors in Swedbank Estonia should have a clear understanding of the 
AML risks. The board of directors is required to approve and oversee that the 
policies for risk, risk management and compliance is relevant in the context of 
AML risks and should request quarterly reports from the CEO of the Bank in 
Estonia of improvements made, including action plan for future measures to 
improve and strengthen AML compliance. 


In order for the organisation to learn, the communication to internal relevant 
stakeholders on the weaknesses in the AML/CTF area must be ensured, amongst 
them, managers and executive management in relevant subsidiaries and on 
Group level. 


5.2.2 Empower staff in the three lines of defense 

Empower Compliance staff with sufficient authority and autonomy to implement 
the new AML program to ensure the implementation is not being compromised by 
revenue interests. 


The Bank has a strategy of three lines of defends to prevent money laundering 
and to ensure AML compliance. It is important that all these three lines of defense 
are empowered to conduct their duties and understand their roles and 
responsibilities. Policies and processes must prevent any risk of 
misunderstanding of roles and responsibilities among first and second line of 
defense that can lead to vital steps not being undertaken appropriately. 


Observations presented in this report might be explained as consequences of 
inadequate organization and structure of the three lines of defense. Both the 
business units and compliance department, responsible for AML, was 
understaffed. There were misunderstandings among employees of their roles and 
responsibilities. Inadequate description of responsibilities and lack of competence 
are some of the weaknesses resulting in non-compliance with AML regulations. 


Strong three lines of defense can, as a general rule, make the Bank more robust 
and able to manage and mitigate the money laundering risk. 


5.2.3 AML risk assessment 

Prepare an updated, factual and real AML risk assessment for the Bank that 
includes the findings and observation from this report and other findings made 
from the off-boarding process in Estonia. 


5.24 AML strategy and program 
Develop an update a formal AML strategy based on the findings from the AML 
risk assessment and observations from the investigation of Focus Clients. 
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5.2.5 Information and training 

Provide periodic AML training for leaders, AML compliance staff, client managers 
and other relevant staff being a part of the three lines of defense, tailored to their 
roles and responsibilities. 


Make sure there are appropriate mechanisms for sharing information of 
suspicious transactions and activities within the organization and for information 
sharing on MLRO level. 


5.2.6 Human and Technological Resources 
Ensure there is sufficient technological and human resources and competence to 
fulfil AML obligations. 


5,27 Testing of the AML program 

The components of an effective AML compliance program include, among other 
components, ongoing risk assessment, risk-based customer due diligence, 
detection and reporting of suspicious activities and independent testing of the 
AML program. 


The third line of defense, the Internal Audit, should be committed to conduct 
internal audit program that would test the AML compliance and sanctions 
regulations and laws. 


5.2.8 Further actions based on identified weaknesses investigation into 
transactions made by clients 

Based on the findings of non-compliance with regulatory requirements, the Bank 

is advised to make a thorough review of the identified weaknesses reported 

during the investigation. The use of straw men, corporate vehicles and entities in 

off-shore jurisdictions have led to high risk for the Bank being involved in money 

laundering. 
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Abbreviations used throughout the report 


AML Anti-money laundering 

AMLO Anti-money laundering officer 

CDD Customer due dilligence 

EDD Enhanced due dilligence 

FATF Financial Action Task Force 

FIU Financial Intelligence Unit 

FSA Financial Supervision Authority 
KYC Know your client 

MLTFPA (Estonian) Money Laundering and Terrorist Financing Prevention Act 
OFAC Office of Foreign Asset Control (US) 
PEP Politically exposed person 

The Bank Swedbank AS Estonia 

UBO Ultimate beneficial owner 

Disclaimer 


This report for Swedbank AB is made by Erling Grimstad, a Norwegian lawyer practicing from Advokatfirmaet Erling Grimstad AS (Norway) 
and member of the Norwegian Bar Association. The ability to engage in any activities on behalf of a client outside Norway is subject to 
statues and professional codes and court rules. Any legal advice or opinion rendered on laws or regulations outside Norway, should be 
consider not necessarily to be within my expertise. You should seek appropriate counsel for specific legal advice outside Norway, to 
understand your position and obligations in accordance with the national law. This report is strictly confidential and contain attorney — 
client privileged information solely prepared for Swedbank AB. 
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SUMMARY 


This report summaries the Anti-money laundering (AML) investigation into Swedbank AS Estonia (the Bank) 
carried out by Advokatfirmaet Erling Grimstad AS in the period February to June 2017 according to the 
mandate. 


While we have only assessed a limited number of clients (the Focus Clients) and corresponding transactions, we 
have identified major breaches of relevant AML regulations pertaining to these high risk non-residential clients 
(individuals and entities), as described more in detail in this report. In our opinion, the non-compliance is 
primarily due to a systemic failure by the local management of the Bank to ensure an appropriate compliance 
culture as well as AML infrastructure to ensure compliance with AML regulations. Inadequate risk management 
systems, risk awareness, competence, resources and governance structure, are seen as major causes of the 
non-compliance with the relevant AML legislation. 


We found that the Focus Clients may have used the Bank for money laundering purposes. The Bank made such 
transactions possible by giving the clients the opportunity to transfer significant amounts in different currency 
to bank accounts controlled by straw men of offshore entities, without fully understanding the real nature of 
business, the interests beyond transactions or questioning the source of funds. We however note that there is 
no concrete evidence of specific profits from criminal origin being transferred by the Bank. 


The lack of an effective and adequate AML programme and the high risk for involvement in facilitating money 
laundering for clients, increased the risk for the Bank and made the Bank attractive for clients who might abuse 
the banking system for money laundering. Enabling clients to transfer value for money laundering, exposes the 
Bank for a significant risk of reputational damage as well as criminal and civil liability. 


The investigation has not revealed any evidence of deliberate or reckless behaviour of the senior management 
of the Bank. 


We are aware that since 2016, the Bank has made several efforts to mitigate the risks identified, to off board 
high risk clients and to build a strong AML framework within the Bank. 
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1. Introduction, scope and objectives 


1.1. Introduction and overview 


On 1 February 2017 Advokatfirmaet Erling Grimstad was given a mandate to investigate matters in relation to a 
group of Swedbank client relationships, referred to by the bank as the Focus Group Clients (hereafter called the 
“Focus Clients”). The Clients broadly consist of a group of clients that are related to a group of companies 


which again are related ои 


The background for the request was that Swedbank was made aware of a possibility that the Focus Clients 
might have been using the bank for money laundering purposes. The awareness was partly brought forward 
through correspondent bank requests and internal findings made by the Swedbank anti-money laundering 
office іп LC&I (AMLO). The suspected activities were to have been transacted through the Swedbank AS Estonia 
(the Bank) subsidiary of Swedbank AB, being part of the business area Baltic Banking. 


The scope of the services was agreed to comprise of the following, divided into two phases: 


е Phase 1: Conduct ап anti-money laundering investigation focusing on the Focus Client relationships for 
the period 2012 – 2016, and 

e Phase 2: Based on observations made during Phase 1, advise Swedbank on process improvements to 
its AML Compliance processes. 


This Report contains the findings and observations of Phase 1 of the Mandate and recommendations based 
thereon. 


1.2. Scope and limitations 


The scope of our AML investigation has been defined by the Mandate. The aim of the AML investigation has 
been to analyse the level of compliance with AML regulations and to identify any major deficiencies in the AML 
control framework. In addition, our tasks have included investigating any possible wrongdoing by employees in 
their handling of the Focus Clients, particularly with respect to identifying any activity or transaction highly 
suggestive of money laundering. 


The aim of the report is also to the Bank a better understanding of the investigated matters should it face 
possible enforcement action from FSA (in Sweden or Estonia) or other authorities. 


We have not investigated entities or persons (including clients of Swedbank) outside the Focus Clients unless 
such omissions, to the best of our knowledge, would render our investigation misleading or incomplete. 
Moreover, our investigation has been purely fact based, and we do not intend to render any legal advice in this 
Report. 


1.3. Objective of the report 
The main objective of this Report is to describe the material findings of our investigation. In reporting our focus 
has been facts and circumstances that may be of relevance to the Bank's potential legal liability, its reputation, 


and/ or that may serve as future learning and competence building (particularly in respect of AML compliance. 


The report does not in any way provide an exhaustive description of all observations made during the 
investigative process. As agreed with Swedbank, we have endeavoured to keep this report relatively short. 


6 of 67 


2. Our approach and methods 


2.1. Methodology used for review and fact finding 
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3.2. AMI regulations and general conditions for engagement with customers 


3.2.1. Directives, policies, relevant mandates and governance rules for the Bank 
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5. Observations and relevant findings 


5.1. Summary 
This section gives a brief overview of the major observation and findings described in this chapter. 


No proper registration or verification of the Focus Clients 

We found no verification of the identity of the ultimate beneficial ownership of the customer. Some of the 
persons acting on their behalf as representatives for some of the entities, was identified and said to be 
employees in the group of entities (Focus Clients). In general, the Bank should not establish a banking 
relationship, or carry out transactions, until the identity of the customer has been satisfactorily established and 
verified. The Bank accepted the disguise of individuals they believed to be beneficial owners, by not 
documenting the beneficial ownership in records. The clients' use of straw men, hiding the real interests 
beyond funds, was accepted. 

The Bank has however internally in KYC documents and credit memos stated the supposed beneficial owners 
and informed the EFSA about the same in their answers to EFSA inquiry. 


The Bank had no proper understanding of the purpose and intended nature of the business relationship or 
transactions for several of the entities being part of Focus Clients. 


Monitoring of transactions 

The lack of information on the business purpose of the individual Focus Clients, made it almost impossible to 
provide the Bank with a meaningful basis for ongoing monitoring of transactions by these clients. We found 
several suspicious transactions, such as questionable payments of dividends, payment for loans, invoices 
suspected to be trade base money laundering, use of nominees or proxies linked to cases of money laundering 
and criminal activity and more. There was no report of any suspicious transactions being investigated or 
reported to the FIU. 


AML program and internal control 

The AML program was inadequate. The Bank did not carry out an adequate and factual risk assessment. The 
directives and policies on AML at the time was not enforced and there was confusion as to roles and 
responsibilities for AML monitoring. 


Facilitation of money laundering 

By accepting to disguise the real owners and keeping no sufficient records of the real relationship, nature of 
business nor the intended nature of transactions, there is a risk of the Bank having facilitated money 
laundering. 


Generally best practice requirements not adopted 
More in general there are several observations made of failure to prudently adopt "best practice" as a 
fundamental concern for the Bank. 


Lack of oversight and supervision - responsibility of the board of directors 
The board of directors has the overall responsibility for adequate AML policies and processes, including strict 


customer due diligence rules to promote high ethical and professional standards in the Bank and prevent the 
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Bank from being used, intentionally or unintentionally, for criminal activities.” This responsibility require the 
board of directors to ensure a sound AML risk program able to address the money laundering risks and to 
oversee that there are adequate and effective policies and processes in the Bank. These responsibilities should 
not be compromised by the financial interests in banking for high risk clients. 


Assessment and understanding of risks require that the employees of the Bank are able to detect and 
understand the money laundering risk, not missing warning signs. Through clearly defined roles and 
responsibilities, the Bank is able to build a strong culture of responsibility from employees for the AML 
program. The effectiveness of the AML program requires proper governance arrangements, especially 
requirements for the board of directors to approve and oversee that the policies, risk management and 
compliance is relevant for the money laundering risks. 


The board of directors should ensure that the Banks policies and procedures are managed effectively. 


Inadequate risk assessment or understanding of the money laundering risks involved with the Focus Clients 
By conducting a comprehensive risk assessment for money laundering risks, based on factual findings as is, 


relevant inherent and residual risks factors can be determined. The risk assessment must include engagement 
with high-risk non-resident clients. The risk assessment should include information from the client 
management database (CMEE), transaction database (Star), products, services, payment channels, jurisdiction 
where clients are doing business, country risk, information of money laundering risks from authorities in 
Estonia, studying of money laundering cases in the region, information from public sources and more. 


From the result of a genuine and factual risk assessment by someone who understand the money laundering 
risk, the Bank should be able determine its risk profile and appropriate level of mitigation. The Banks policies 
and procedures for customer acceptance, customer identification and monitoring of business relations and 
operations should consider the results from the risk assessment. 


No effective lines of defence 


We identified understaffed business units and compliance departments responsible for AML. Misunderstanding 
among employees of their roles and responsibilities and inadequate description of responsibilities and lack of 
competence are understood to be factors resulting in non-compliance. 


Strong three lines of defence can, as a general rule, make the Bank manage and mitigate the money laundering 
risk: 

- Тһе first line of defence being the business units, front office and the employees facing the clients. 
They should have sufficient resources to identify, assess and control the money laundering risks of the 
business they are responsible for. It is extremely important that the business units understand the 
requirements in the KYC process and fully know their customers, their identity, nature of business, 
source of fund and wealth and are able to detect any suspicions of money laundering from their 
clients. 


- The second line of defence being compliance, responsible for the monitoring of the business units and 
the fulfilment of the AML duties of the Bank. 


-  Astrong Internal Audit has an important role as the third line of defence conducting independent 
evaluation of the risk management, oversee controls in place and evaluate the effectiveness of 
compliance with AML policies and ргоседиге5,3233 


Culture of compliance 
Effective AML program require a culture of compliance not compromised by the financial interests of the Bank. 


The culture of compliance is essential to protect the Bank from the abuse by clients to transfer value for money 


31 Sound management of risks related to money laundering and financing of terrorism, Basel Committee on Banking Supervision, June 
2017, Essential elements of sound ML/FL risk management. 

32 Intrnal Audit Report issued 29/12/2016 from GIA on КҮС Renewal Process іп Balktic Banking, inclusing Estonia, described findings of 
insufficient KYC renewal process, lack of adequate governance and intrnal control and agreed actions. 

33 Internal Audit Report issued 4/10/2011 of Management, Valuation and Reporting of Problematic Investments in the Portfolios of 
Discretionary Asset Management Customers of Swedbank Baltic Banking did not address the AML risk. 
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laundering purposes. Findings and observation gave us an impression of a weak culture of AML compliance and 
poor understanding of the need to protect the Bank from the money laundering risk from high-risk non- 
residential clients. The board of directors and supervisors are able to influence the culture of the AML 
compliance organisation by their requirements to staff, oversight of the AML program and constant informing 
and address inadequate and ineffective performance from employees. 


Findings and observations presented in chapter 5 

Further in this chapter, we describe the observations and findings that are, as per our understanding, the most 
important for the Bank at the time of submission of the report. The findings and observations described in this 
report are based on the information we had until finalizing the work at agreed date. 


5.2. Basis for the findings and observations 


5.2.1. Sample testing of KYC information 


5.2.2. Sample testing of transaction data 


| 
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Ехатрје – Anonymous email addresses 
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5.4.7.1.1. Business and private transactions for Focus Clients 


5.4.7.1.2. Other detailed examples of transactions reviewed 


5.4.7.1.2.1. Example wa 
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6. Recommendations 


1) Board of directors 


2) Empower staff in the three lines of defence 


3) AML risk assessment 


4) AML strategy and program 


5) Information and training 
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6) Human and Technological Resources 


7) Testing of the AML program 


8) Further actions based on identified weaknesses 
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2018-01-03 
Andreas Hobbelin 
Håkan Bengtsson 
To Swedbank Group CCO 


Swedbank Estonia transactions with Danske Bank 
and exposure to the Magnitsky case 


Department: Group Compliance, special AML Task Force ы. 

In beginning of 2017 Group Compliance established a special AML Task Force ("АМ:ТР") for ifvestigation and off- 
boarding of specific group of clients of Swedbank Estonia. AMLTF has since then also Worked with follow up;on Estonian 
AML Issues as well ав AML issues In Latvia and Lithuania. А? b. 4 


Introduction ж 


been possible to extract and review. Тһе report will also highlight certain other relevant transactions. 
м Ұз 

In the beginning of Septeniber 2017 Danske Bank vias reported to be involved іп the Azerbaijani Laundromat with 
transactions performed by its Estoniarí;branch. Оп21 September 2017, Danske Bank launched a press release, stating 
that they would expand its investigátion into ifs Estoniàn branch‘, On 11 October 2017, Danske Bank launched а new 
press release, stating that {һеу бад ben placed under investigation by the French Tribunal de Grande Instance de Paris 
court in relation to suspicions of money laundering concemlng transactions carried out by customers of Danske Bank 
Estonia from 2008 to 20442 related to the Magnitsky case, and Inherently linked to the Russian Laundromat and the 
Billion doller bank fraud in Moldova. Fürthérmore it could be mentioned that Danske Bank accepted a fine from Danish 
FSA in December 2017; as,reboited on 21 December 2017, and relating to violation of Danish AML rules". Also in 
September 2017, members ofthe European Parliament called for investigation into the Azerbaijan! Laundromat and 
adoption of the Magnitsky АВЕ. 

Ж VERR ы. 7 
Conipanles/individuals mentioned below and marked іп BOLD аге or has been clients of Swedbank Estonia. And 
compahies/individuals that are UNDERLINED are related to above mentioned ML cases without being cllents of 
Swedbank;Estorífa: 


Summary 


Swedbank initlal review of transactions between Danske Bank and Swedbank was performed by Baltic Banking Internal 
Anti-Financial Crime & Investigation Service (AFCIS), which performed thelr transaction analysis with main focus on the 
highlighted companies tn the Azerbaijani Laundromat. Findings in the report from AFCIS, reveals that clients of 


—ə.—-[, .  — = 

| https://danskebank.com/news-and-insights/news-archive/press-releases/20 17/pr21092017 

+ https-//danskebank.com/news-and-insights/news-archive/company-announcements/2017/ca1 1102017 

k hittps:/danskebank. com/news-and-insights/news-archive/company-announcements/201 7/ca2 1 122017 

4 http://www.europarl.europa.eu/news/en/press-room/2017091 JIPR835 16/meps-call-for-an-investigation-into-azerbaijani-laundromst 
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Swedbank Estonia had performed transactions with two companies mentioned in the Azerbaijani Laundromat ФФ 
чир ani 1j However, these payments were performed between 2012 and 2014. 


AMLTF requested additional transaction data from Swedbank Estonia on all USD payments from 2008 to 2011. Due to 
the size of data, additional review including other currencies such as EUR will be made If findings in USD payments 
indicate reasons for additional analysis in other currencies and as will bé agreed with Swedbank CCO, 

From previous investigations and transaction analysis, AMLTF has transaction data from Swedbank Estonia for the 
period from 2012 until February 2017 on 8 specific group of former clients belonging to what is known in the Bank as the 
Focus Clients от. which is also related to the former LC&l cien | The Focus Clients has 
performed several of hundreds of incoming and outgoing payments with clients of Danske Bank also from 2008 and 
2011. 


Zx, 


` 


In addition to transaction data, request was made to Swedbank Estonia to provide any underlying documents based:on 
m~ request from authorities, corresponding banks or law firms relating to the Magnitsky case. Swedbank EstoniajproVided 
two Internal documents from March 2013 showing previous efforts performed by the Bank. One document named 
Payments from Clients of Sampo related to Magnitsky.doc showed 8 Swedbank Estonia Clients performing transactions 
with clients of Danske Bank Estonia reportedly linked to the Magnitsky case. 2 ^ 
And another document named MEMO Magnitsky, pof, created on 3 March 2013 by local AML Officer Swedbank Estonia 
and Head of Compliance & Operational Risk, Baltic Banking, revealed certain direct links,to companies in the Magnitsky 
case. 

During 2008-2011, there were 6.667 incoming payments (USD.Z:222 759 481) from clients of Danske Bank to clients of 
Swedbank Estonia, and 3.788 outgoing payments (USD 1 951 342 465) from,Swedbank Estonia clients to clients of 
Danske Bank Estonia. 235 clients were incorporated in the following low tax jurisdictions (offshore and onshore); 
Switzerland, Belize, Dominica, Switzerland, Cyprus, Gibraltar, Hong Копо šle of Man, St. Kitts & Nevis, Luxembourg, 
Marshall Islands, Malta, Panama, Seychelles, Singapore, St; Vincent.& Grenadines, British Virgin Islands. 

In respect of those offshore and onshore clients, there were 2.278 outgoing payments (USD 1 785 424 355) to clients of 
Danske Bank, and 1.955 incoming payments (USD 1:666 710/716) from clients in Danske Bank to clients in Swedbank 
Estonia. Majority of Danske Bank clients were companies incorporated in low tax jurisdictions or LP/LLPs controlled by 
offshore companies. A majority of both the clients of Swedbank Estonia and of Danske Bank Estonia have limited visible 
business activity, most probably.just functioning as shell companies. 


т Findings 


A. Danske Bank cliénts exposure to Magnitsky case 


According to 1 Azerbaijani Laundromat, the n UK — 5 had accounts with Danske Bank Estonia; ЕР 


4 is а [ERE 
' 
a ү 
DE cC MEN ne ana as General Partners; both companies have been 
identified as,haying ол as beneficial owner is identified as owner and co-owner in 
former Swedbank : NN and with links to sanctioned 
companies controlled by sanctioned individual is also linked to the 
mentioned in articles and open sources as holding shares in qe 
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B. Swedbank Estonia clients exposure to Magnitsky case 
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The followina companies and transactions have been identified: 
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Conclusion 
Based on the performed review and currently available information and trafisactions, itcould be concluded as follows; 


4. The review of transactions between Swedbank Estonia and Danske BankEstonia during 2008 — 2011 shows 
several direct links to companies/parties being linked ла ће Magnitsky case (and other ML cases). 

2. Тһеге are certain facts that could lead to the conclusion that several,transactions most probably could have 
been seen as suspicious, and thus to be reported 'to.FIU if those would have been scrutinized at the time for 
execution. In this respect it seems obvious thatthe bank didn't monitor and investigate high risk transactions in 
a sufficient way. š : 

3. Basedon the material that we currently have been able to extract there are no clear evidence that obviously 
shows that the transactions between:Swedbank Estonia and Danske Bank Estonia are directly linked to 
transferring of money in the Mágnitsky case, however there are several transactions between companies linked 
to the case which per se irídicates that there, could be connections to the Magnitsky case and/or other 
illegitimate money involved in:the transactions. On the other hand it could be that the counterparties had 
legitimate business between themselves or that it could be suspicious transactions based on other assumptions 
than the link to the Magnitsky case. 
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Amendment 


To the report re Swedbank Estonia transactions with Danske Bank 
and exposure to the Magnitsky case, dated 2018-01-03, to 
Swedbank Group CCO 


This amendment Is meant as а clarification of findings in the report Swedbank Estonia transactions with Danske Bank 
and exposure to the Magnitsky case and as regards the questions if certain mentioned counterparties are still clients of 
the bank or off-boarded since earlier. 


© Swedbank 
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From: Håkan Bengtsson <trakan.bengteson@swedbenk.com> 

Sent: 2018-08-13 12:52:01 +0000 

To: Mads Blomfeldt <Mads.Blomfeldt@bdo.no>; Andreas Hobbelln <andreas.hobbelln@swedbank.no> 
Subject: RE: Sendt fra Utkfippsverktay 

Attachments: 20180711 - Memo on new names In media - Danske.pdf 

Enl tel 


From: Mads Blomfeldt [maBito:Mads.Blomfeldtgbdo.no] 
Sant: den 13 augusti 2018 14:35 

To: Andreas Hobbelin; Håkan Bengtsson 

Subject: Sendt fra Utkippsverktøy 


КОРОР ||__ ПИ ________ ни 


Mossago Hoaders: Received: from SRV63092.fspa.myntet.se (10.8.33.65) by SRV63093.fspa.myntet.se 
(10,8,31,66) with Microsoft SMTP Server (TLS) Id 15,0.1365,1 via Mallbox 
Transport; Mon, 13 Aug 2018 14:52:02 +0200 
Received: from SRV62318.fspa.myntet.se (10.8.33.61) Бу SRV63092.fspa.myntet.se 
(10.8,33.65) with Microsoft SMTP Server (TLS) Id 15.0.1365.1; Mon, 13 Aug 
2018 14:52:01 +0200 
Recelved: from SRV62318.fspa.myntet.se ([fe90::498e:aaa8:7bdb:d9ba}) by 
SRV62318.fspa.myntet.se ([fe80::498e:aaa8:7bdb:d9ba%21])) with тарі Id 
15.00.1365.000; Mon, 13 Aug 2018 14:52:01 +0200 
Content-Type: application/ms-tnef; names"winmall.dat" 
Content-Transfer-Encoding: binary 
From: Håkan Bengtsson <hakan.bengtsson@swedbank.com> 
To: Mads Blomfeldt <Mads.Blomfeldt@bdo.no>, Andreas Hobbelin 
<andreas.hobbelln@swedbank.no> 
Subject: RE: белді fra Utklippsverktøy 
Thread-Topic: Sendt fra Utklippsverktgy 
Thread-Index: AdQzAetUK+9kR1WfSAOZvDAEsX3L9QAAnIAA 
Date: Mon, 13 Aug 2018 14:52:01 +0200 
Message-ID: <1e75eb6805264145b8958b65ec323491 @SRV62318.fspa.myntet.se> 
References: <AM4PRO501MB19718C296AD2745F0B7869F9FA390@AM4PRO501MB1971.eurprd05, prod.outiook.com> 
In-Reply-To: <AM4PR0501MB1971BC296AD2745F0B7869F9FA390 @AM4PR0501MB197 1.eurprd05.prod.outiook.com> 
Accept-Language: sv-SE, en-US 
Content-Language: en-US 
X-MS-Has-Attach: yes 
X-MS-Exchange-Organization-SCL: -1 
X-MS-TNEF-Correlator: <1e75eb6805a64145b8958b65ec323491@SRV62318.fspa.myntet.se> 
MIME-Version: 1.0 
X-MS-Exchange-Transport-FromEntityHeader: Hosted 
X-MS-Exchange-Organization-MessageDiractionality: Originating 
X-MS-Exchange-Organization-AuthSource: SRV62318,fspa,myntet.se 
X-MS-Exchange-Organization-AuthAs: Internal 
X-MS-Exchange-Organization-AuthMechanism: 04 
X-Orlginating-IP: [10.8.33.6] 
X-MS-Exchange-Organizatlon-Network-Message-Id: 7e109c5f-Gbf1-421a-60db-08d6011b9075 
Return-Path: hakan.bengtsson@swedbank.com 
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Danske Bank involvement in money laundering schemes - new links 


Iptemabiemoezcentidentiol 


SUMMARY 


Media corporations published in the beginning of July 2018 new articles regarding Danske Bank 
Involvement in money laundering schemes, 


In addition to historical media coverage back from 2017 following company names were mentioned as 
new: 


None of abovementioned entities have been direct customers of Swedbank Baltic entities. 


In order to assess Swedbank Involvement 651 conducted the counterparty search 01.01.2007 until 
05.07.2018 and identified that: 


- Swedbank customers received 13 incoming payments from 


- Period of named payments was Мау 2007 until August 2008; 
- Total amount across Baltics was 1.061 394 EUR out of which Estonia received 883 000 EUR; 
- |nallcases counterparty bank was Danske Bank Estonian branch. 


Background _ 


In the beginning of July 2018 in media there was a new article regarding Danske Bank involvement in 
money laundering schemes. 


Source: 
In addition to historical media coverage back from 2017 following names were mentioned: 


a 
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STRICTLY GONFIDENTIAL - NOT ТО BE SHARED WITHOUT THE EXPLICIT CONSENT OF THE CEO 


Baltic Banking’s exposure mainly related to Danske 
Bank Estonia case 


Peta WASP те ONERE GULE 


lo Бе/аБіе о а 
Е Er Pu шш “Тһе D eres ое Б 
n intormalion torgooni However, с due to Фе extended internal investigation initiated! by/ Danske} 
ap el /'itSJESt9) ап Branch as descr bedin several media ап јез, Gomplispeen ated investigation; 
‘betweer Banking and Danske) Bank Estonia БЕЛІ Th purpose, 


с ‘of UI 
Š ) К ) П 
р 52. E 
t ae "a 


Я 


1 The decisions vs. Deutsche Bank particularly pointed out Estonia as problematic. 


STRICTLY CONFIDENTIAL: not to be shared without consent of 
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4.1 Group Compliance, special AML Task Force 


Early 2017 Compliance established GGAMLTF for investigation and нона, of spec fo groups of clients of 
Swedbank Estonia, internally known as project Clear”. Project Clear was closed: 137 hay, 2017 and involved 
very few Swedbank employees and a few external well known specialists wan s afea of financial crime. 


Since then work with follow up on Estonian AML issues as well as АМЫ faros 'in Latvia and Lithuania has been 
carried out. Hence, since June 2017, GCAMLTF has initiated 4 НОАМ! workshops/sessions^ and has 
analyzed parts of the client portfolios within all Baltic countries, Gi: айп апа advising оп ће overall money 
laundering risk in each country's client portfolio. The work has al ig ipdluded detailed assessments of the money 
laundering risks within hundreds of clients, includin advising on off-boarding of clients; enhanced EDD, 

mitigating actions and analysis etc. Due to findings, GCAMLTF tus initiated and supported the development of a 
Baltic Banking Moriey Laundering Risk Portfolio лову 4 


Since January 2018, GCAMLTF has monitored” initpeiformed transaction analysis on foreign paymente in Baltic 
Banking’, for the purpose of following up ) on the progress of AML work related to specific transactions". 


In addition, work was initiated to Scr cuni а des and/or transactions due to negative media artlcles, such as 
DBE, ABLV bank and FBME Балка ñ other issues that have been identified during the work. 


Due to the: amount of work das compliance and money. laundering risks in Baltic Banking and the fact 
that it is perceived as к involve local staff — before more facts are on the table - due the structures and 
potential conflicts of ‹ tef st {ееп different external/internal stakeholders, most of the work has been 
performed by али outside normal tasks and normal working hours. 


„б, + 
1.2 Scope s“ ES bs 


Due to һе "ektended internal investigation initiated by DBE as described by Press Releases from DBE, a 
transattion'a nalysis mirroring the same time period was initiated by Compliance, The purpose of the investigation 
was “toa ча чад earlier unknown or пої sufficiently addressed issues relating to transactions between DBE and 
Swedbank Estonia, Latvia and Lithuarila between 2007 to 2015. 


The investigatfön is based on transaction data made available by Baltic Banking to GCAMLTF during the 


? Compliance staff involved In preparing this memo is in total four. 
3 Also known as “Focus clients”. All actions in project Clear have been documented, including IT logs etc., and analysis have 
been stored at a special server where only a very few limited employees have been given authorization ав precautionaty 
measures, The documentation is stored within Group Information Security. 
ч , Mainly performed by Håkan Bengtsson and Andreas Hobbelin supported with the GS! employee Sven Klwistik. 

$ Not to be confused with the Baltic ML Risk Assessment, however the ML Risk Portfolio Analysis shall give input to the Risk 
Assessment. 
7 Post-transactions, not related to the AML Compliance transaction monltoring of Nice Actimize alerts. 

Per month. 
5 Focusing on LP/LLP ahd offshore companies. 
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spring/summer of 2018. In order to identify transactions between the clients of Baltic Banking and the clients of 
DBE that are considered questionable or suspicious from an ML/TF/Financiat Sanction perspective, the following 
high risk indicators have been used: 


° Companies with no or limited visible business activity or a business activity that could not be identified 

e Companies incorporated in offshore/onshore jurisdictions (including also Hong Kong and Delaware) 

• Companies controlled by offshore companies with no or limited business activity (including UK legal 

entities, e.g., Limited Liability Partnership “LLP” and Limited Partnership "LP") 

e Companies incorporated in UK and New Zealand with proxy/nominee Directors and/or shareholders 

e Companies profiled in Panama Papers and with links to Mossack Fonseca 

• Companies profiled in Offshore Leaks, Paradise Papers, Bahamas Leaks, or Swiss Leaks 

e Companies with links to money laundering, corruption, fraud and illegal arms trade cases? 

e Transactions related to project Clear gt : 

e Large single transactions 2% y mM 

& VS 

In this context it is also essential to understand the magnitude of the information retrieved, which. &orrespond to 
141 557 KB, where the tools to analyze this kind of information is inadequate and has been made'by in excel. 


4 


This report should по! be considered ав ап entirely full overview or ( in-depth scrutiny of all 
suspicious/questiohable transactions between DBE and Baltic Banking as not all'tfansactions between the banks 
that could be of relevance have been possible to extract and review together«With underlying documents 
supporting thé transactions. The тајп focus of the investigation has therefore'bean to check the counterparties of 
DBE. As Nr 


Furthermore, the report does not contain or tias the intention to contain ë detailed description of each transaction 
that is considered as questionable and/or suspicióus. Detailed descriptions on underlying transactlons considered 
as questionable? and/or Suspicious can be given on request and: willthen be preserited in the form of xlsx sheets 
in personal meetings. However, some selected case examples will be shown in the report in order to understand 
the context. , Мм 

% 


2. Result VN 
4% % Уа 

2.4 Overall result of the investigation қ”; 

ы” “ * 
Between 2007 and 2015, Balli¢"Banking clients"! performed 15 902 transactions with questionable and/or 
suspicious counterparties of, DBE;«to the amount of incoming EUR 618 953 225 and USD 105 822 186 and 
outgoing EUR 1 422 574:588‘ап9 150 2654 210 307. The peak of these transactions was between 2011 and 
2013, whereof 10 725, transactions where performed. This could be compared to the DBE money laundering 
case, which according [0 recént leaks is estimated to be approx. EUR 7.5-8 bn. 


"m 
7 Source of funds > 
Æ 618 953 225,00 
SWBB Source of funds DBE 
Misc. dients Æ 1 422 574 588,00 : Misc,:questionable/suspicious clients 


2 


"Russian Laundromat, Azerbaijani Laundromat, Magnitsky case, Moldova Bank Fraud, Deutsche Mirror Trade, Odessa Network or other 
adverse publicity cases 


Questionable clients' means companies with either no or limited visible business activity, or could not be identified, or 
incorporated in offshore/onshore jurisdictions, or controlled by offshore companies or incorporated in UK (e.g., LP/LLP, LTD), or 
New Zealand with proxy/nominee directors and/or secretary, or incorporated in Hong Kong and Delaware with no information on 
Directors/owners or other visible business activity, or profiled in e.g., Panama Papers (Mossack Fonseca), Offshore Leaks, 
Bahamas Leaks, Paradise Papers, Swiss Leaks. 

+ Domestic and foreign. 


а ÉÁÉ———————üb i ААА 
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а: of funds 
% 105 822 186,00 
SWBB Source of funds wr 
Misc. clients $£ 2 654 210 307,00 Misc. questionable/suspicious clients 


In addition to. performing questionable and/or suspicious transactions, many of the clients of Baltic Banking 
performing these transactions, where incorporated themselves in offshore jurisdictions and considered as 
questionable. The most frequently offshore jurisdictions found to be used by clients are British Virgin Islands, 
Belize, Marshall Island, Seychelles, Panama, Cyprus, and St. Kitts and Nevis. Other jurisdictions have also been 
New Zealand, UK, Hong Kong, and US low tax-low transparency states Delaware, Oregon and Nevada, as well 
as Canada. 


The following sections (2.2-2.7) will provide more detailed information of what has been seen in the: jvestigation 
in relation to different customer and transaction segments. 


2.2 UK counterparties with legal form Limited 


Case examples 


2.3 New Zealand Companies 


Case examples 
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It could also be noted that there are several transactions with UK "LTD" companies linked tô EE | 
|| — y proxies/nominees used у аш « u^ , 


2.4 BVI incorporated companies 


D 


ВМІ incorporated companies are found fo be frequently used both in clients t Bultic Banking and clients of DBE, 
many of these BVI companies are profiled in the database of the International Consortium of Investigative 
Journalists С) under Рапагпа Papers, Offshore Leaks, Bahamas Leaks, Paradise Papers, and Swiss Leaks. 
However, the majority of findings relates to companies profiled * in Panama Papers and Offshore Leaks. 
Companies/individuals profiled in Panama Papers are linked to Mossack Fonseca, and in Offshore Leaks to 
Commonwealth Trust Ltd., which in many cases are “linked, to, Unitrust Corporate Services and International 
Offshore Services (IOS) and are similar to Mossack Fonséga®. 


Case example Mossack Fonseca ы. № 
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2.5 LP/LLP companies 


UK and Scottish Limited Liability Partnership (“LP”, “ПІР” companies have been reported by media and other 
bodies such as Transparency International?” and the UK National Risk Assessment??, as frequently“used as 
vehicles for money laundering, fraud, corruption and illegal arms trade cases in several cases recent years. They 
are commonly used with proxy/nominee individuals both as Directors and Persons of Significant Control ("PSC"), 
and proxy/nominee shell companies being incorporated in offshore jurisdictions as General Partners. This non- 
transparent setup, often with the use of the same proxy/nominee individuals or offshore/shiéll companies, makes 
clients transactions with suspicious LP/LLP counterparties difficult to disprove. In ‘addition to the money 
laundering risk connected with LPALLP companies, this non-transparent setup that conceal beneficial owners can 
also be used to avoid sanctions?" 


Between 2007 and 2015, several of hundreds of clients™ of Baltic Banking performed transactions with LP/LLP 
counterparties of DBE, with a total amount of outgoing EUR 65 958 344 ‘and"USD 203 836 071, and Incoming 
EUR 126 476 133 and USD 207 703 695. The majority of these LP/LLPs are controlled by offshore companies” 
linked to alleged money laundering, corruption, fraud and illegal arms: rade Cases? 


. SWBB Source of funds 
Misc. clients Ф 203 836 071,00 


= Source of funds Se | 
£ 126 476 133,00 


SWBB Source of funds DBE 
Misc. cients Ж. 65 958 344,00 LP/LLP dients 


4” 
а» 


Source of funds 
% 207 703 695,00 


Se 
DBE 
LP/LLP dients 


Furthermore ‘the investigation has identified 12 clients of Baltic Banking, the majority of these clients belonging to 
Swedbank; Estonia with the UK legal form Limited Partnership "LP" and "Limited Liability Partnership "LLP", 
Between 2007 and 2015, these 12 LP/LLP clients of Baltic Banking performed transactions with questionable 
ап ог Suspicious counterparties of DBE, to the amount of outgoing EUR 3 192 957 and USD 24 236 205 and 
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incoming EUR 13855 148 and USD 15 427 552. The majority of these clients are being controlled by offshore 
companies involved in alleged money laundering, corruption, fraud and illegal arms trade cases. 


Case examples 


2.6 Transactions related to project’ Clears 


Between 2007 and 2015, преси ‘Ciéar clients, being clients of Swedbank Estonia, have performed 1599 
transactions with clients ог DBE that are considered as questionable and/or suspicious, to the amount of outgoing 
USD 1 378 075 457 and EUR 963 451 635, and incoming USD 19 144 132 and EUR 402 019 057. Transactions 
performed by these ! Gompaniés have been both to questionable and/or suspicious counterparties in DBE, as well 
as to other project ‘Clear companies with accounts in DBE. 


54 саша of funds =i 
£ 402 019 057,00 GD 
SwBB Source of cic 4 DBE 


"Project Clear" clients £ 963 451 635,00 Misc. questionable/suspicious clients 


_____________________- nan OO 
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5. 
Source of funds Se 
#19 144 132,00 
SWBB Source of funds DBE 


"Project Clear" clients % 1 378 075 457,00 Misc. questionable/suspicious clients 


The transactions illustrated below examples were not discovered in Project Clear due to the amount of 
information and the fact that some companies had already left the bank, as part of the increased attention of the 
Group towards the companies involved in project Clear, which involved more than 200 companies. 


Case examples 


2.7 Large singe transactions 

Between 2007 and 2015, several large payments have been performed between Baltic Banking clients and 
clients of DBE. Several of these payments have béen performed by both questionable and/or suspicious clients of 
Baltic Banking and counterparties of: DBE. ~. · 


Case examples 
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d. Conclusion 


m 


The majority and the biggest amounts of questionable and/or suspicious transactions are made by clients of 
Swedbank Estonia. However there seems to be different kind of modus operandi between the three Baltic 
countries depending on currency, incoming or outgoing payments and type of counterparties (e.g., LR/LLP, LTD 


or similar). f % 


GCAMLTF has not had access to ай client files, full account stätements ог underlying documentation!süpporting 
transactions. Without being able to scrutinize the single transactions ‘and underlying documentation supporting 
the transactions it is not possible to assess how many of the transactions between Baltic, Barking. апа DBE that 
should have been reported às suspicious tó the respective FiU?', However, as seyeral, money laundering 
indicators have been identified in the transaction data, there are grounds to believe that more transactions should 
have been reported to the FIU and more clients should have been off-boarded estar than actually done. 


The large exposure of USD payments to questionable and/or suspicious counterparties, many with links to 
Mossack Fonseca, and other alleged money laundering, corruption, fraud and illegal arms trade cases, increases 
the risk for Swedbank to be approached by US authorities. In this context it i is\worth noticing that Swedbank got a 
request from US (NYDFS) in the spring of 2018 on clients affiliated: with Mossack Fonseca”. In addition, the 
amount of incoming and outgoing payments between Baltic Banking, in particularly Swedbank Estonia, and DBE, 
can increase the risk for Swedbank to be approached both by Estonian and Danish authorities given the recent 
media articles indicating a very high amount of money bairig allegedly laundered via DBE. 


Finally, the transaction monitoring/analysis of foreign’ paymanis in Baltic Banking show that Baltic Banking still 
has а risk exposure to ІРЛІР and offshore countérparties, Only in May 2018, clients of Baltic Banking performed 
16359 transactions with LP/LLP companies, {0% thé amount of incoming EUR 3 187 204 and USD 187 860 and 
outgoing EUR 516 045 and USD 288 743. Some’ of these LP/LLP companies are controlled by proxies/nominee 
Directors and offshore/shell өні мін < 45 "General Partners linked to alleged money laundering, corruption and 
illegal arms trade cases” жы“! 


4. Recommendations and actions 


k 
То mitigate any potsfitiäl risks of Swedbank being used for money laundering/terrorist financing activities and any 
risk that could follow. from authority's scrutiny of Swedbank including negative risks on Swedbank's reputation and 
negative corisequences for correspondent banking relationships and funding, Swedbank Compliance 
recommends 'doing the following: 


** 4 April 2013 
s - https: lloffshoreleaks.icij.org/nodes/216088 
% As set out above, similar to Mossack Fonseca 
5 STRISAR historical reports in the Baltics have not been matched against this Danske Bank data 
$ This Inquiry excluded Baltic Banking, which was confirmed by our US legal advisors. The exclusion was made clear in the 
submitted answer 
ы 5 Only foreign payments above EUR 5 000 


ne 
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Follow up on Swedhank's risk exposure in relation to the investigation of ML issues in Danske 
Bank, Estonia 


Internal Memo/Coufidertial = not to be spread to anyone without the express consent of the 
ГЕО of Swedbank AB (publ) 


| Background 


{ This memo is a follow up to previous reported risk exposure between Swedbank Baltic 
‚ Banking (Swedbank) and Danske Bank Estonia (DBE)'. 


| This memo is intended to give an overall oversight and insight into questionable 
transactions and to describe the risk related to Swedbank in relation to the investigation of 
money laundering (ML) issues in DBE - and especially customers and counterparties incl. 
their transactions that could be linked to the problems in DBE. It has not been possible at 

| this stage to relate the numbers in this investigation to the numbers revealed In the DBE 


| Report (defined below). | 0 АКАЙ 


| Due to the big amount of data and transactions the investigations and analysis have been 
limited to (i) questionable transactions and parties, based on decided specific risk | 

| indicators that have been applied? during the period 2007-2015 and also thresholds for 

‚ amounts. Hence, not all transactions between Swedbank and DBE have been analysed. 


| Further, the portfolio investigation has been made using a risk based approach based on 

: the decided risk indicators. Both former and current customers in Baltic Banking have been 

| run against these risk indicators and grouped based on the perceived risk. A transaction- 
by-transaction approach has not been adopted in this phase of the investigation. This is 

| due to time- and resource restraint, but also since this until now has not been deemed ` 

| necessary“. Thus, some clients are only identified with one single transaction to/from these 

‘clients of DBE, while others have several transactions. | 


! Dated 2018-07-12 distributed only to a few internal stakeholders. 

2 The risk Indicators used are (i) legal form”: L.P, LP, LLP, LTD, LIMITED, LLC, INC, CORP, S.A. (more legal forms have later 
been detected as relevant, e.g., GMBH, A.G, A/S (Danish legal form), however transactions with these have not bean 
significant in comparison to the others) (1) payment description: "loan", "refund", "repald", "return" (more payment details have 
been found as relevant, e.g., “consulting”, "corporate service", however transactions which Includes these have not been 
significant In comparison to the others) (ili) currency: EUR (included EEK converted to EUR), USD have been used. Other 
currencies GBP, RUB and, CHF have been Identified but are not included In the amounts set out in this memo since they are 
deemed not to be significant and (№) counterparty (clients of DBE). 

` EUR 5000 for domestic payments and EUR 2500 for foreign payments. 

* After having taken part of the "Report on the Non-resident Portfollo at Danske Bank's Estonian branch", made public 
2018-09-19, (the DBE Report) Compliance can conclude that this is the same approach that has been used by DBE. 
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| The fact that former or current customers have been linked/involved in some suspicious 
| payments does not necessarily imply that such payments or all of their payments were 
| suspicious. 


| The investigations and analysis have been done by Compliance, with the assistance of the 
| external consultant BDO. 


| А comprehensive way of describing the risk that Swedbank is exposed to when it comes to 
| AML/CTF risks is by describing the networks and links that our clients are associated with, 
|as is shown in certain examples in Appendix ЛЫ 


| 
| Key takeaways: 
| 


| Тһе following most important takeaways are’: 


| 
| 1) None of the entities that have been mentioned in media in the DBE case has been 


identified as customers of Swedbank based on transaction with DBE. (Only a few 
of the concerned DBE customers have so far been named in media.) 


i 


2) The investigation shows, that approx. 3440 of Swedbank's former and current 
customers have conducted transactions with counterparties of DBE and their 
networks, whereof approx. 2000” are current customers. 


3) The turnover of identified questionable/suspicious cilents and/or counterparties with 
transactions with DBE (the "Flow")” amounts to approx. EUR 3 200m and approx. 
USD 6 700m from 2007 till 2015, which comprises both former and current clients. 


| 4) 29 clients of Swedbank, of whlch 11 are still customers, have been identified as 
| non-acceptable. They have been directly matched against the list of the Russian 
| Laundromat companies published by the Organized Crime and Corruption 

i Reporting Project (OCCRP). 163 counterparties, i.e. clients of DBE, on the same 

| ОССЕР list have made transactions with Swedbank's customers, both former 

| and current clients. 


5) 35 former clients of Swedbank, which all are UK registered LPs/LLPs, have 
performed transactions with clients of DBE. At least 17 of these former clients are 
controlled by some of the most infamous offshore companies and 
proxy/nominee directors linked to organized corruption and money 
laundering. In addition, these former LP/LLP clients are linked by transactions to 
other LP/LLP companies, some mentioned in relation to Magnistky, Azerbaijani EL. 


———————————— 


* Still In draft form 


by BDO, which means that there could be some changes in the data. 

7 As eet out in footnote 7, the data, which currently matches 1986 cllents, is not fully confirmed. However, for the sake of 
simplicity the number 2000 is used throughout the memo at this point. 

* We are for this purpose using the term as the ОВЕ Report in order to be able to *compare". However, it should be noted that 
from what we understand the flow In the DBE Report is the total flow in DBE Estonia (not limited to flow to/from cartain banks). 
However, the DBE Report only covers the so called Non-resident Portfolio and It is unclear what this precisely comprises, The 
investigation carried out by Compliance, could have identified customer and counterparties of DBE not covered by the Моп- 
resident Portfollo. 
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related to ОВЕ. 


6) At least 237 clients of Swedbank, mostly former, identified іп the Flow have a 

| positive match against the Investigative Consortium of Investigative Journalists 
| (ICIJ) database/lists ("ICIJ"), whereof at least 74 are linked to Mossack Fonseca 
("МЕ"). 


7) Atleast 350 counterparties (i.e. clients of DBE) of Swedbank’s customers have 
| a positive match against ICIJ, whereof at least 100 are linked to MF. 
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1 Background _______ 


DBE has repeatedly been accused of facllitating money laundering by the Danish business 
paper, Berlingske, The allegations have also been broadcasted by other media and 
organisations and the problems around DBE has also lead to investigations from authorities 
in Denmark and Estonia but also France; both in general as regards the bank as well as 
regarding possible criminal actions towards employees. The result of the investigation done 
by DBE was published in the DBE Report. 


It seems that Berlingske, as well as OCCRP, have access to internal documents and 
account statements from DBE customers. Based on those documents it has been concluded 
that accounts of non-resident companies (e.g., includes NZ, UK, PA, BZ, etc.) in DBE were 
used to transfer funds originating from several worldwide organized money laundering 
scheme, including the following (according to published іпо) 2: 


- Magnitsky - Transactions comprising DKK 28bn, during 2007-2015 connected to 
Russian tax fraud: named after the lawyer S Magnitsky, who died in a Russian prison 

- Moldova - Transactions comprising DKK 7bn, during 2011-2014 connected to tax fraud 
and corruption etc. involving Russian organized criminals 

- Azerbaijani Laundromat - Transactions comprising DKK 18bn, during 2012-2014 
connected to fraud and corruption also pointing at European officials and politicians 

- Russian Laundromat - Transactions value not revealed, but conducted during 2007- 
2015 connected to companies alleged controlled by the family of Putin and FSB. 

- Deutsche Bank Mirror Trading. 


It should also be noted that Bill Browder filed a report in July 2018 pointing at 26 former and 
current employees of DBE, accusing them of money laundering and other criminal activity. 
Ultimo July, the Estonian State Prosecutor's Office announced that criminal investigation has 
been started based on this report." The Danish Prosecutor's Office has informed about 
launching similar investigation in Denmark. The DBE Report also states that 42 employees 
and "agents" have been deemed to have been involved in some suspicious activity and 
where DBE is in the process of filing SARs to the Estonian FIU and further that they have 
reported 8 former employees directly to the Estonlan police. 


This memo is intended to describe Swedbank's risk as regards Swedbank's customers, their 
counterparties and their transactions which could be directly, or to some extent indirectly, 
linked to the problems in DBE and the customers in DBE that has been mentioned in the 


е media, which аге only а handful, while sources talks about several hundreds. 


how speclal payments to employees was organized, 
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E Scope of the investigation, available data and sources and who has been involved 


3. Customers, counterparties and the Flow 
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Swedbank 6%? 
"5. Existing customers that can be connected to DBE ML issue or other ML issues 


Further, more detailed information of the existing customers connected to DBE is presented 
FA in Appendix 2. 
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6. The way forward. - Proposed actions to be taken 
—— ard - Proposed a 


waar 


A. Principles for risk appetite 


—R 


The proposed principles are as follows; 
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From: Cecilia Hernqvist SMYNTET/FIRST ADMINISTRATIVE 
GROUP/RECIPIENTS/P999CHE> 

Sent: 2018-09-23 16:18:48 +0000 

To: Birgitte Bonnesen <birgitte.bonnesen@swedbank.se> 

Subject: 

Attachments: 180927 Memo on AML_CTF.docx; 180727 The Board of Directors.pptx 

Hej, 

Hej, 


Bifogat memo och ppt, ppt är ì princip klart, subject till dina kommentarer förstås, de tar mer upp vad 
vi gjort maa av D eftersom resten dagliga arbetet står i memot 


Memot behöver jag kolla några saker på som du kommer se, skrev det från minnet, har datastrul och 
har inte allt i huvet även om jag har mkt... 


Se båda som utkast och har försökt vara så pedagogisk jag kan för att förklara risker och utmaningar 


Lösen kommer på mess 


Håll i hatten när du läser det och låt oss diskutera 


Ha det skönt//Cecilia 
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Prepared for: The Board of Directors of Swedbank AB 


Memo on how Swedbank work with anti money laundering (“AML”), Combating Terrorist 
Financing (CF) and Financial Sanctions ("FS") 


27 September, 2018 


1. Background 


This memo will on a general level and not in-depth describe how Swedbank works to prevent 
Money Laundering ("ML")/Terrorist Financing ("TF") and the efforts done in recent years to 
better understand both the compliance risks as well as our ML/TF risks. 


This memo does not focus on financial sanctions ("FS"), which due its nature is a more 
political tool. This is not to say that sanctions are not important. They are important, esp. for 
our relationship with our US correspondent banks and the fact that US regime comes down 
hard on non-compliance with sanctions. 


2. What is the typical risk in ML/TF/FS? 


As in all risk categories, one has to distinguish between the compliance risk and the risk for 
ML/TF/FS. The compliance risks comprises that we do not follow all rules related to the area. 
The МІ/ТЕ! risks, are the risks that we are used for ML/TF. The perception that we are used 
for ML/TF/FS is a reputational risk, which is clearly shown in Danske Bank?. Further, both 
compliance risks and ML/TF risks often comprises operational risks?. The risks are of course 
linked in that way that if one risk is at hand this may lead to the others. 


Where does the risk occur? 


In every step there is ML/TF/FS/Compliance risks 


1. “On-boarding/lifecycle"; typical compliance risks are that we do not have enough 
information about the customer or do not react adequately 


1 The FS risk mainly contains compliance risk, but depending on transaction it could also comprise ML/TF risks. For instance in 
connection to Danske Bank, there is media articles mentioning that payments have been going through Danske Bank related to 
illegal arms trade to North Korea and Azerbajdzjan. Danske informed at their press-conference on Wednesday last week, that 
they have not found any breaches of financial sanctions. 


2 Danske Bank's share price has been severely affected by the allegations on ML/TF. The investigation that has been carried 
on for one year has cost them DKK 200m so far, and they are not finished. They have gone through approx. 6000 customers 
out of 15.000 related to the so called Non-resident portfolio and the report states that Danske has had 70 FTE working with this 
for one year. It should also be noted that, according to media, there are ongoing investigation by the US authorities since the 
last two years. 

Poor processes, lack of competence and resources. 
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2. "Swedbank/banks”; typical compliance risks are that we do not have adequate framework 
that are implemented, not good enough tools and processes” and ? 


3. "In-and outgoing payments and other transactions (FX trades, transfers between own 
accounts etc.,)"; typical compliance risks comprise: 


4. “On-boarding/lifecycle/Swedbank/banks/in-and outgoing payments and other 
transactions"; typical ML/TF/FS risks are that: 


09-27 (18-09-23) Мето оп АМЕ_СТЕ , 2021-01-14 10:56 diarienr: 9000-K822-19 


3. Why are ML/TF/FS risks different from risks? 
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4. А simplified way to show the work done to prevent, detect and respond 


5. How does the organization look like? 


6. What has the FSA's said? 
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7. What has been done in recent years? 
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8. What special efforts have been done due to recent cases mentioned in media? 
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9. What are the challenges? 
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[E-postmeddelande, 2021-01-14 10:56 diarienr: 9000-К822-19 | u | 251 | 


и: 


From: Cecilia Hernqvist SMYNTET/FIRST ADMINISTRATIVE 
GROUP/RECIPIENTS/P999CHE> 

Sent: 2018-09-23 16:18:48 +0000 

To: Birgitte Bonnesen <birgitte.bonnesen@swedbank.se> 

Subject: 

Attachments: 180927 Memo on AML_CTF.docx; 180727 The Board of Directors.pptx 

Hej, 

Hej, 


Bifogat memo och ppt, ppt ari princip klart, subject till dina kommentarer förstås, de tar mer upp vad 
vi gjort maa av D eftersom resten dagliga arbetet star i memot 


Memot behöver jag kolla några saker pa som du kommer se, skrev det fran minnet, har datastrul och 
har inte allt i huvet även om jag har mkt... 


Se båda som utkast och har försökt vara sa pedagogisk jag kan för att förklara risker och utmaningar 


Lösen kommer pa mess 


Hall i hatten nar du läser det och låt oss diskutera 


Ha det skónt//Cecilia 
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МЕМО ге certain issues related to 
High Risk Non-Resident Customers 
of Swedbank Estonia 


2019-01-25 


Prepared by Swedbank Compliance 


1. Background 


In July/August 2018 Swedbank Compliance initiated an investigation in order to identify if 
former or current employees of Swedbank Estonia might have been connected to clients or 
transactions that could expose Swedbank to heightened risk situations in the light of what 
was informed in media around the Danske Bank case, and especially taking into account 
alleged money laundering and wrongdoings from employees in Danske Bank. The 
investigation was not only limited to transactions or client responsibilities etc. connected to 
Danske. 


The investigation was handled by the CEO of Swedbank Estonia with assistance from GSI 
within Baltic Banking/Estonia ("Internal report"). The Internal report was issued 2018-09-27 (see 
section 2). 


Hereafter Compliance decided to engage an external law firm in order to review the Internal 
report from Estonia, but also to further investigate possible AML violations and possible 
wrongdoings and liabilities for employees in respect of certain High Risk Non-Resident clients 
(HRNR) in Swedbank Estonia. The reason for taking over the internal investigation was due to 
possible conflicts of interest within Swedbank Estonia, including GSI. The law firm delivered a 
draft report 2018-12-10 based on the assignment (see section 3) and which included certain 
recommendations. 


This memo sets out the recommendations from the external law firm, and comment on them 
from the Group's perspective also taken into consideration meetings and discussions with the 
law firm, the last such meeting on 2019-01-15. Thus, below Swedbank sets out its view on the 
recommendations as well as its actions and reasons why Swedbank currently will not follow a 
recommendation, as the case may be. The standpoints as set out in this memo might need to 
be revised based on developments and/or if new information or circumstances would occur 
(section 4 below). 


Information class: Internal and Confidential 
Page 1 of 8 


Restricted access (If applicable): The CEO Swedbank AB (publ) and the external law Тіпті mentioned in this memo 


2. Investigation and analysis by GSI Estonia 
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3. Investigation and analysis by Advokatfirmaet (Law firm) 
Erling Grimstad 
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4. Recommendations by Advokatfirmaet (Law office) Erling 
Grimstad and the banks considerations and actions based 


thereon 
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Chief Compliance Officer 
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ERLING GRIMSTAD 


Address: Gaustadalléen 21, 0349 Oslo, Norway 
T: (447) 997 97 542 е Email: eg@governance.no 
Web: www.governarice.no 


Swedbank AB 
Swedbank Compliance 


To be sent by email to: Cecilia. hernqvist @swedbank.com and 
hakan.bengtsson@swedbank.com 


Autor in charge: Ering Gumistad 


Oslo, 30 January 2019 


COMMENTS TO THE MEMO RE. CERTAIN ISSUES RELATED TO HRNR CUSTOMERS 
OF SWEDBANK ESTONIA 


Background 

We are asked to give our general, as well as more spesific comments, on the Memo from Swedbank of 
25 January 2019, In the Memo, Swedbank Compliance states that the memo “sets out the 
recommendations [rom the external law firm, and comment on them from the Group's perspective also 
taken into consideration meetings and discussions with the law firm (...)". Wilh reference to our meeting 
with Swedbank 15 January 2019, we understand that Swedbank have decided to give their comments 
and reasons why Swedbank will not follow a specific recommendalion as stated in our Draft Preliminary 
Status Report of 10 December 2018. We fully respect this decision. 


Based on our assignment and the assessment done of the GSI report of 27 September 2018, we 
sincerely cansidered our ability to give detailed comments on the memo of 25 January 2019 from 


Swedbank Compliance. Our conclusion and the reasons for this conclusion, is explained in this letter 


Summary of our work for Swedbank AB 
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ERLING GRIMSTAD 


Our preliminary assessment of the GSI investigation was not an inve 


Conclusion 

As stated in the memo from Swedbank Compliance dated 25 January 2019, we understand that 
Swedbank do not accept our most significant recommendations. We respect the decisions made by 
Swedbank Compliance. 


However, and based on this, we have concluded that we are not in any position to comment on the 
more detailed considerations and remarks from Swedbank as regard to the recommendations. The most 
important feedback from us in this letter is to remind Swedbank of the work we actually did for 
Swedbank and the serious breaches of anti-money laundering regulations identified, which pose great 
risks for Swedban based on our best knowledge and analysis. 
Ж. / 
A, ) 
/ 
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Signerat av 


Rapport 


Myndighet 
Ekobrottsmyndigheten 2018-09-20 Follow up on Swedbank's risk exposure Signerat datum 


Enhet Diarienr 


Stockholm FMK 9000-K 822-19 
Orginalhandlingens férvaringsplats | Datum Tid 
2021-01-20 12:47 
Involverad personal Funktion 
Ann-Christin Sandén Uppgiftslämnare 


Berättelse 


Beslag 2019-9000-BG297-6 i ärende 9000-K564-19. 


Follow up on Swedbanks risk exposure in relation to the investigation of ML issuses i Danske 
Bank, Estonia, daterad 2018-09-20. (se infogad fil) 


Till rapporten finns två bilagor: 


Appendix 1, Example clusters to illustrate Swedbank Baltic's exposure to high risk entities. 
(se bilaga) 


Appendix 2, Statistics re existing clients exposure to DBE, 2018-09-21. (se bilaga) 


Rapporten finns även som inkommen handling 2019-03-12 från Finansinspektionen men 
utan de två bilagorna. 
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4 Follow up on Swedbank's risk exposure in relation to the investigation of ML issues in Danske 
Bank, Estonia 


Internal Memo/Confidential - not to be spread to anyone without the express consent of the 
CEO of Swedbank AB (publ) 


SUMMARY 


! Dated 2018-07-12 distributed only to a few internal stakeholders. 

2 The risk indicators used are (i) legal form”: L.P, LP, LLP, LTD, LIMITED, LLC, INC, CORP, S.A. (more legal forms have later 
been detected as relevant, e.g., GMBH, A.G. A/S (Danish legal form), however transactions with these have not been 
significant in comparison to the others) (ii) payment description: “loan”, "refund", "repaid", "return" (more payment details have 
been found as relevant, e.g., “consulting”, "corporate service", however transactions which includes these have not been 
significant in comparison to the others) (iii) currency: EUR (included EEK converted to EUR), USD have been used. Other 
currencies GBP, RUB and, CHF have been identified but are not included in the amounts set out in this memo since they are 
deemed not to be significant and (iv) counterparty (clients of DBE). 

3 EUR 5000 for domestic payments and EUR 2500 for foreign payments. | 

4 After having taken part of the "Report on the Non-resident Portfolio at Danske Bank's Estonian branch", made public 
2018-09-19, (the DBE Report) Compliance can conclude that this is the same approach that has been used by DBE. 
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Still in draft form 

в Please note that the numbers of customers matched in different segments as well as stated amounts still are under validation 
by BDO, which means that there could be some changes in the data. 

"де set out in footnote 7, the data, which currently matches 1986 clients, is not fully confirmed. However, for the sake of 
simplicity the number 2000 is used throughout the memo at this point. 

8 We are for this purpose using the term as the DBE Report in order to be able to "compare". However, it should be noted that 
from what we understand the flow in the DBE Report Ís the total flow in DBE Estonia (not limited to flow to/from certain banks). 
However, the DBE Report only covers the so called Non-resident Portfolio and it is unclear what this precisely comprises. The 


investigation carried out by Compliance, could have identified customer and counterparties of DBE not covered by the Non- 
resident Portfolio. 
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1. Background 


DBE has repeatedly been accused of facilitating money laundering by the Danish business 
paper, Berlingske. The allegations have also been broadcasted by other media and 
organisations and the problems around DBE has also lead to investigations from authorities 
in Denmark and Estonia but also France; both in general as regards the bank as well as 
regarding possible criminal actions towards employees. The result of the investigation done 
by DBE was published in the DBE Report. 


It seems that Berlingske, as well as OCCRP, have access to internal documents and 
account statements from DBE customers. Based on those documenis it has been concluded 
that accounts of non-resident companies (e.g., includes NZ, UK, PA, BZ, etc.) in DBE were 
used to transfer funds originating from several worldwide organized money laundering 
scheme, including the following (according to published info)? : 


- Magnitsky - Transactions comprising DKK 28bn, during 2007-2015 connected to 
Russian tax fraud; named after the lawyer 5 Magnitsky, who died in a Russian prison 

- Moldova - Transactions comprising DKK 7bn, during 2011-2014 connected to tax fraud 
and corruption etc. involving Russian organized criminals 

- Azerbaijani Laundromat - Transactions comprising DKK 18bn, during 2012-2014 
connected to fraud and corruption also pointing at European officials and politicians 

- Russian Laundromat - Transactions value not revealed, but conducted during 2007- 
2015 connected to companies alleged controlled by the family of Putin and FSB. 

- Deutsche Bank Mirror Trading. 


It should also be noted that Bill Browder filed a report in July 2018 pointing at 26 former and 
current employees of DBE, accusing them of money laundering and other criminal activity. 
Ultimo July, the Estonian State Prosecutor's Office announced that criminal investigation has 
been started based on this report. The Danish Prosecutor's Office has informed about 
launching similar investigation in Denmark. The DBE Report also states that 42 employees 
and “agents” have been deemed to have been involved in some suspicious activity and 
where DBE is in the process of filing SARs to the Estonian FIU and further that they have 
reported 8 former employees directly to the Estonian police. 


This memo is intended to describe Swedbank’s risk as regards Swedbank’s customers, their 
counterparties and their transactions which could be directly, or to some extent indirectly, 
linked to the problems in DBE and the customers in DBE that has been mentioned in the 
media, which are only a handful, while sources talks about several hundreds. 


12 https://www.b.dk/nationalt/enolish-version-an-overview-of-the-ganske-bank-money-laundering-scandal ^ 

13 The Estonian media hae also published an interview with an anonymous person who clalmed that he/she is aware of 
practices that wére used by the non-resident department of DBE. The source explained among other things how new clients 
were recruited and how the internal setup and 'service packages' made alleged money laundering in DBE possible, including 
how special payments to employees was organized. 
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3, Customers, counterparties and the Flow 
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_4, Identified customers/transactions of non-acceptable and high risk character | | — 74. Identified dentified customers/transactions ‘of non-acceptable and high risk non-acceptable and high risk character — 
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Top transactions - off-boarded clients with special interest 
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5. _5. Existing cu customers thi that can be connected to DBE ML issue or other ML issues ___ can be connected to DBE ML issue or other ML issues 


Further, more detailed information of the existing customers connected to DBE is presented 
in Appendix 2. 


09-20 Follow up on Swedbank's risk exposure, 2 
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6. The _6. The way forward — Pre forward — Proposed actions to be taken | | | | __ actions to be taken 


Principles for risk appetite 


The proposed principles are as follows; 


Existing 2000 clients identified in the Flow — Monitoring and possible off-boarding and possible off-boardin 


11 


rt 2018-09-20 Follow up on Swedbank's risk exposure, 20 20 12:47 diarienr: 9000-К822-19 — 


swedbank & 


apport 2018-09-20 Follow up оп Swedbank's risk exposure, 2021-01-20 12:47 diarienr: 9000-K822-19 


Swedbank @ 


‘Rapport 2018-09-20 Follow up оп Swedbank's risk exposure, 2021-01-20 12:47 diarienr: 9000-К822-19 349 


Swedbank @ 


14 


350 


Bilaga 
Appendix 1 


Bilaga till Externt dokument 2021-01-20 12:47, diarienr 9000-K822-19 


Beskrivning 


351 | 


| Appendix 1, 2021-01-20 12:47 diarienr: 9000-K822-19 


e d PES AUR 3 
| ao о ты 
- k = Wes Я > 
27 m Y 
"Hm ELM 
а 2 > 
” 
. 
. 
> 


sannue 155/48! 


Pa oJ 2215009 S pes ued ромс 


1815 Вг № 
гі Хы et Ф. 


a е 2 
dL. да 
i ee coL 
Lu ve Sör « = 
-£ 
жоо. is > 
« = = = iE x ге = x= эзш see RSS “= 
Se Є 2 a = —- an M UR 4E Go = = 
eo 2x ес SU *& Ко em, cv i ж oye Ғы” © 
` š ‘a cae ht En = we Qo Арырак СЫЗ | po RU. E ШАҒЫН š Ew esc 


m 
Е 
~ 
& 
< 
"6 3 
Se. 
а” 
"аа 
“г. * 
9 Ж 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-К822-19 352 


Background 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-K822-19 | | __ 353 


Swedbank Baltic's exposure 2007-2015 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-К822-19 u | 354 | 


Network 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-К822-:9 — 


NOOT әлоде- SJOMION 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-К822-19 | | — 356 


d his role in known МЕ cases... 


is, an 


Description of Who 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-K822-19 = | 357 


Swedbank Ва с5 exposure 2007-2015 


Appendix 21-01-20 12:47 diarienr: 9000-К822-19 


| Appendix 1, 2021-01-20 12:47 diari 


SOOT глоде — JJOMI2N 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-К822-19 


= 
g 

> 
T3 

Q 
= 
Q 
Е 
Y) 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-К822-19 | mul | 361 


Description of | 


Appendix 1, 2021-01-20 12:47 diarienr: 9000-К822-19 _ | | | 362 


Swedbank Baltic's exposure 2007-2015 
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Swedbank Baltic's exposure 2007-2015 
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Тор exposed clients (by amount) 
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Top exposed clients (by amount) (2) 
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Top 10 profit Small Business (without CM) 


Latvia 
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Toomas Tuuling 
AML Officer Swedbank AS 01.03.13 


Johan Rosén 
Head of Compliance & Operational Risk, Baltic Banking 


TO: Hakan Berg 
Cecilia Hernqvist 
Birgitte Bonnesen 
Helena Nelson 


CONFIDENTIAL 


Internal MEMO 


Тһе MAGNITSKY CASE and Swedbank іп Estonia 


There are at this point no significant legal or compliance risks identified related to this 
case. There is, however, reputational risk because of possible negative media 
coverage. 


INTRODUCTION 


In 2007 Russian subsidiaries of Hermitage were allegedly raided by Russian police and then 
used by state officials as vehicles for stealing USD 230m of tax money from Russian treasury 
in a faked tax refund. Sergey Magnitsky was a tax lawyer who was working for Hermitage 
and who during his investigation discovered this fraud scheme. Nevertheless, after blowing 
the whistle on the case, he was incriminated for the same tax fraud he discovered and 
subsequently died in prison from mistreatment. 

All this money was paid out from the state Treasury and subsequently laundered using many 
banks and offshore companies in different jurisdictions, Including Russia, Latvia, Lithuania, 
Estonia, Cyprus, Switzerland and Moldova. 


Many states, including Switzerland and Lithuania have started criminal investigations related 
to this case. In July 2012 attorneys of the law office of Brown Rudnick, who represents 
Hermitage Management Limited (the investment advisor to Hermitage Fund), filed complaints 
to Latvian and Estonian authorities, The Latvian complaint we soon found on the Internet but 
the Estonian complaint was forwarded to us as late as today by media. 


Disclosing pretrial info in criminal cases is strictly regulated by law and can be disclosed only 
by authorization of the prosecutor. If info is not leaked to media or it is not disclosed by 
authorities, then it is not possible for us to know about this kind of complaints. This is how it 
was in Estonia. 


THE ACCUSATION 

In Latvia several well known non-resident banks were mentioned and in Lithuania Ukio 
Bankas in regards to this case. In Estonia Sampo (Danske) and Hansapank (Swedbank) are 
named as banks through which money has been laundered. 


The complaint sent to Estonian prosecutors office and the FIU is a request to start an 
investigation into a possible breach of the Estonian laws on Money Laundering and anti- 
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Corruption. Brown Rudnick specifically claim that there is an apparent failure of due diligence 
in that the companies through whose accounts the money travelled were apparent shell- 
companies. 


MEDIA 


In January 2013 the Magnitsky case was in Estonian media for the first time in this context, 
but at that time no Estonian banks were directly mentioned (FIU declined to comment). There 
was an interview with the head of the Estonian FIU regarding this case and possibilities of 
starting/not starting criminal investigations. The press also implied that there are problems 
with due diligence in Estonian banks, Because of this Swedbank was asked for a comment 
and after that it calmed down. 

At the end of February 2013 Eesti Päevaleht presented the extract of the Estonian complaint 
to Swedbank and Danske for comment, because they had now info who exactly was involved 
in Estonia. 


THE MONEY TRAIL IN SWEDBANK 


CONCLUSIONS AND ACTIONS 
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CURRENT STATUS AND RISK 


There are at this point no significant legal or compliance risks identified related to this 
саве. There is, however, reputational risk because of possible negative media 


coverage. 
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DOES SOMETHING NEED IMPROVEMENTS? 
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Stockholm FMK 9000-К822-19 
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2021-01-21 16:02 
Involverad personal Funktion 
Björn Sandman Uppgiftslämnare 


Berättelse 


2017-09-13 Memo re the Azerbaijan laundromat (Danske Bank Estonia) 

2017-09-12 Activities taken on the Azerbaijani Laundromat media Coverage 

2017-09-13 Mejl från Håkan Bengtsson till Birgitte Bonnesen med ovan två Memon som 
bilagor. 


Mejlbeslag 2019-9000-BG294-1, 
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Prepared for; CEO 
Memo re the Azerbaijan laundromat (Danske bank Estonia) 


Confidential 


Prepared by 


Håkan Bengisson on behalf of Charlotte Elsnitz 


1. Background 


During the first week of September 2017 there were several articles in media on Danske bank Estonia 
in relation to alleged money laundering connected to Azerbaijan. The articles explicitly named certain 
companies to which large sums of money should have been routed from Danske bank in Estonia. In 
the articles certain main companies were mentioned as receivers of funds through Danske bank; i.e. 


SS (the "Main 


Companies”). 


Based on available information of named entities and individuals, and other related parties, actions 
was taken together with Baltic Banking AFCIS and in cooperation with local compliance in order to 
identify potential association to named entities or transactions that could be linked to Swedbank 
Estonia (as Estonia was explicitly pointed out) or Swedbank in Latvia or Lithuania. 


li. Conclusions/status from investigation as of today, 2017-09-13 
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Prepared for: To whom it may concern 


Activities taken on the Azerbaijani 
Laundromat media coverage 


Status Update Memo 


Confidential 


Date: 2017/09/12 


BACKGROUND 


During 04.09.2017 - 06.09.2017 there were several articles in media on Danske bank Estonia 
relations to Azerbaijani Laundromat scheme. 


https://www.theguardian.com/world/2017/sep/04/everything-you-need-to-know-about-the-azerbaijani- 


laundromat?CMPzshare Ып link 


http://www.aripaev.ee/uudised/2017/09/04/aserite-pesumasin-ule-2-miljardi-huugas-labi-eesti 
ittp;//www.aripaev.ee/uudised/2017/09/05/aseri-pesumasinas-liigutasid-miljoneid-ka-eesti-firmad 


varbas 


http://www,.aripaev.ee/uudised/2017/09/06/rehe-juhitud-da nske-oli-offshorkade-paradiis 


JIWWW. айраем.е i 17/09/04/aserite-pesumasina-osaline-oli-Jüri-Moisa-firma-kli 


The AFCIS EE compiled a list of involved companies. In total there are 173 entities and individuals 


listed: main concern is related to companies x üw БЕНЕН 
EB and BERNER: however aim of the full list was to identify Swedbank customers 


potentional association to toxic entities. 


In cooperation with Compliance Estonia there was verified that Swedbank Estonia do not have direct 
customer relationship with the listed companies and individuals. 


PanBaltic IT request to identify customers transactions connected to listed subjects was completed. 
The IT request was based on name search only (according to data available., therefore matches 


needs to be verified to work further e.g. Wai W WE: however preliminary results 


as of 12" of September 2017 can be shared. 
Status as of 12th of September 2017 


Swedbank Estonia customer 's transactions with listed subjects 2012-2017 


INTERNAL AND CONFIDENTIAL Page 1 of 6 


2017-09-12 Activities taken on the Azerbijani Laun, 2021-01-21 16:02 diarienr: 9000-K822-19 


1. Main concern is related to companies. URN НИ 7 


2017-09-12 Activities taken on the Azerbijani Laun, 2021-01-21 16:02 diarienr: 9000-К822-19. — _408] 


Swedbank @ 


Swedbank Latvia customer s transactions with listed subjects 2012-2017 


201 Activities taken on the Azerbijani Laun, 2021-01-21 16:02 diarienr: 9000-K822-19 


2. Main concern is related to companies TSS i! БЕНЕН ond 


2017-09-12 Activities taken on the Azerbijani Laun, 2021-01-21 16:02 diarienr: 9000-K822-19 


Swedbank 


Swedbank Lithuania customer's transactions with listed subjects 2012-2017 


3. Main concern is related to companies ff. i БЕНЕН ond 


2017-09-12 Activities taken оп the Azerbijani Laun, 2021-01-21 16:02 diarienr: 9000-К822-19 412] 


Swedbank @ 


413 


Bilaga 
2017-09-13 Mejl Danske Azerbadjan 


Bilaga till Externt dokument 2021-01-21 16:02, diarienr 9000-K822-19 


Beskrivning 


2017-09-13 Mejl Danske Azerbadjan 
Från Håkan Bengtsson till Birgitte Bonnesen 


Kopia till Charlotte Elsnitz, Cecilia Hernqvist 
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From: Håkan Bengtsson <hakan.bengtsson@swedbank.com> 

Sent: 2019-03-07 13:27:16 +0000 

To: Håkan Bengtsson <hakan.bengtsson@swedbank.com> 

Subject: FW: FW: Danske Azerbadjan 

Attachments: Danske AzerbadjanHB.docx; Appendix AFCIS SK Azerbaijani Laundromat status 12092017.docx 


From: Håkan Bengtsson 

Sent: den 13 september 2017 15:16 
To: Birgitte Bonnesen 

Сс: Charlotte Elsnitz; Cecilia Hernqvist 
Subject: Danske Azerbadjan 


Birgitte, 


Attached please find a memo re actions in connection with the media re Danske and Azerbadjan transactions and as agreed 
with Charlotte. 


I also attach a more detailed description/appendix of certain transactions etc, compiled by AFCIS / Sven K. 


Sorry for the delay. 


BR // Håkan 


cc Cecilia H 


Message Headers: Received: from SRV63094.fspa.myntet.se (10.8.33.66) by SRV62318.fspa.myntet.se 
(10.8.33.61) with Microsoft SMTP Server (TLS) id 15.0.1367.3 via Mailbox 
Transport; Thu, 7 Mar 2019 14:27:16 +0100 
Received: from SRV62318.fspa.myntet.se (10.8.33.61) by SRV63094.fspa.myntet.se 
(10.8.33.66) with Microsoft SMTP Server (TLS) id 15.0.1367.3; Thu, 7 Mar 2019 
14:27:16 +0100 
Received: from SRV62318.fspa.myntet.se ([fe80::498e:aaa8:7bdb:d9ba]) by 
SRV62318.fspa.myntet.se ([fe80::498e:aaa8:7bdb:d9ba%21)) with тарі id 
15.00.1367.000; Thu, 7 Mar 2019 14:27:16 +0100 
Content-Type: application/ms-tnef; namez"winmail.dat" 

Content-Transfer-Encoding: binary 

From: Hakan Bengtsson <hakan.bengtsson@swedbank.com> 

To: Hakan Bengtsson <hakan.bengtsson@swedbank.com> 

Subject: FW: Danske Azerbadjan 

Thread-Topic: Danske Azerbadjan 

Thread-Index: AdMskgYRsJkpx5OgSpySogb9/M013GoV29cw 

Date: Thu, 7 Mar 2019 14:27:16 +0100 

Message-ID: <d46e7ff5c71b42e787d0e559ce3a057e@SRV62318.fspa.myntet.se> 
References: <c83e49d651684a7388d6f103 1db28fdf@SRV62318.fspa.myntet.se> 
In-Reply-To: <c83e49d651684a7388d6f1031db28fdf@SRV62318.fspa.myntet.se> 
Accept-Language: sv-SE, en-US 

Content-Language: en-US 

X-MS-Has-Attach: yes 

X-MS-Exchange-Organization-SCL: -1 

X-MS-TNEF-Correlator: <d46e7ff5c71b42e787d0e559ce3a057e@SRV62318.fspa.myntet.se> 
MIME-Version: 1.0 

X-MS-Exchange-Transport-FromEntityHeader: Hosted 
X-MS-Exchange-Organization-MessageDirectionality: Originating 
X-MS-Exchange-Organization-AuthSource: SRV62318.fspa.myntet.se 
X-MS-Exchange-Organization-AuthAs: Internal 
X-MS-Exchange-Organization-AuthMechanism: 04 

X-Originating-IP: [10.8.33.6] 

X-MS-Exchange-Organization-Network-Message-Id: 92132de2-85a5-49c9-c144-08d6a3009dc9 
Return-Path: hakan.bengtsson@swedbank.com 
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Logg över händelser utifrån MAR/CMI perspektiv med anledning av UG1, EG-rapporten och 
BDO-rapporten 


Nedan logg visar diskussioner som förts i samband med att Uppdrag Granskning sände sitt första avsnitt 
(UG1) om penningtvätt, och huruvida en insiderlista ska upprättas. 


Nedan logg sammanställer även huvudsakligen delar hänförliga till utkast till rapporten ”Draft 
Preliminary Status Report on AML” av den norske advokaten Erling Grimstad, i denna logg benämnd som 
EG-rapporten. Rapporten är ett utkast i vilket EG sammanfattar de findings han gjorde vid sin utredning 
av AML-hanteringen i bankens estniska dotterbolag, samt förslag på åtgärder. Enligt uppgift fick banken 
del ау EG-rapporten den 10 december 2018. 


Nedan logg behandlar även den s.k. BDO-rapporten, daterad den 20 september 2018. 


Datum Händelser relaterade till UG1 Dokument | 
2019-02-19 | Diskussion förs över mail huruvida insiderlista ska öppnas med Іш 
anledning ау informationen att UG ska sända ett program от | Т 
й ЖЕКЕШЕ = | Mailväxling Öppning 
penningtvätt där Swedbank är med | av lista 2019-02-19 dc 


2019-02-19 | Fortsatt diskussion om eventuell öppning av insiderlista bestående | e 7 
ау еп mindre grupp som enligt uppgift hade тег bakomliggande 
information om vad som skulle beröras i programmet. Information 
till Gregori i efterhand om hur diskussionerna gått 2019-02-20 


Fortsatt mailväxling 
om öppning av lista 2 


нм 
Protokoll СМІ 
20190220 utan adden 
* и 
Addendum.pdf 
2019-02-22 | Mail skickas ut till GEC där man avråder från handel i Swedbanks | 1 
finansiella instrument. Den 25/2 skickas mail igen till GEC där de 
uppmanas att vidarebefordra mailet till relevanta personer samt Крот А 
att dokumentera vilka det skickas till. __ | | 
2019-03-01 | EdF mailar Ragnar Gustavii (RG) och tar upp frågan om | әр 
ordförandeskapet i СМІ, och intressekonflikter som uppstår. 


BILAGA LOGG Mail om 
CMI Chair 2019-03-01 
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Datum Händelser relaterade till EG-rapporten och BDO-rapporten 


| 
2019-03-26 | Medlemmarna i СМІ erhåller mail från Gabriel Francke Rodau med | 
utkast av artikel från Uppdrag granskning (UG) innehållande 
påstådda citat från EG-rapporten. Eventuella kommentarer från 
banken skulle lämnas senast kl 13 till reportern. 


2019-03-26 | Utkastet till artikel skickas samma dag av Nene Bjerström Galvan | 
(NBG) till Gustav Skogö (GS) och Johan Josjó (JJ) ра GDA för hjälp 
med bedömning av innehållet ur ett insiderperspektiv. 

Det konstateras att CMI inte fått del av själva EG-rapporten, vilket | 
gjorde att det var svårt att göra en korrekt bedömning av 
insiderfrågan enbart utifrån innehållet i utkastet till artikel. 


——" | _ = 
| 2019-03-26 | SVT publicerade artikeln på eftermiddagen. 


2019-03-29 | Eva de Falck (EdF) får del av EG-rapporten i samband utskick till 
styrelsen med anledning av att styrelsen begärt att få ta del 
rapporten. Kl 21.30 diskuterar EdF rapporten vid telefonmöte med 
JS och GS). Diskussionen avsåg huvudsakligen frågan om EG- 
rapporten utgjorde insiderinformation eller inte. Det 
konstaterades att CMI inte känner till vilka överväganden, 
avseende insiderfrágan, som gjordes i december när banken 
(Compliance) fick del av rapportutkastet. Det föreligger risk att 
innehållet i utkastet borde ha bedömts utgöra insiderinformation 
när den kom. Det bör dock beaktas att det rör sig om ett utkast och 
inte en slutlig rapport. För det fall innehållet ska anses som 
insiderlnformation bör det ha varit fallet även i december, varför 
det konstaterades vara för sent att nu göra en bedömning. | 
| Marknaden har dessutom nu fått del av vissa delar av rapporten. 


EdF har vid ett flertal telefonmöten med GDA diskuterat frågan hur 
banken bör behandla rapporten utifrån ett insider perspektiv 
(varav några samtal redogörs för I denna logg). I telefonsamtalen 
konstaterades bland annat att rapporten är ett utkast, att CMI inte 
känner till bankens/Compliance’s inställning till rapportens 
innehåll (håller man med om vad som anges eller anser man att i 
vart fall delar inte är korrekta), samt att CMI inte känner till vilka 
åtgärder, om några, som vidtagits med anledning av 

| rapportutkastet. 


Dokument 


CMI meeting minutes 
- artikel Ес-гарр 2019 


+ 


Nene Bjerström Galvan (NBG) far del ау rapporten. Konstateras att 
Gabriel Francke Rodau och Gregori Karamouzls, bade ledamöter ау 
CMI, inte har fått del av rapporten pga. beslut att begränsa 
spridningen. Konstateras vidare att Anders Karlsson har utsetts till 
| tf VD och inte längre är CFO, vilket innebär att han Inte längre ingår | 


2019-03-31 
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2019-04-01 


2019-04-02 


2019-04-02 


2019-04-03 


2019-04-03 | 


i CMI (uppdraget var knutet till hans tjänst som CFO). 


NBG återkoppling och avstämning med bl.a. GS. 

KI 22.00 - telefonmöte (EdF, NBG, Håkan Bengtsson(HB), 
Compliance, samt GDA — JJ, GS, Niclas Rockborn (NR), Daniel 
Waerme (DW)). Syfte att diskutera frågan och rådgöra med GDA 
hur informationen i EG-rapporten ska bedömas samt hur 
eventuellt offentliggörande eller uppskjutande ska bedömas och 
hanteras. HB redogjorde bl.a. för bakgrunden till rapporten. HB 
konstaterade att rapporten var i utkastform, tagits fram under 
mycket kort tid, samt att banken hade vissa synpunkter på den, 
vilka hade kommunicerats till EG. 


EdF lyfter tre frågor med Anders Karlsson | 

1. Compliance kvartalsrapport från Q1 2016 delas med styrelsen ` 

2. Hur ska EG rapporten hanteras ur ett insiderperspektiv юм 
3. CMI fungerar inte i sin nuvarande form | 

GDA tar fram förslag till kommunikation/pressmeddelande runt 

rapportutkastet. Fortsatta diskussioner med GDA avseende 

informationens karaktär och om innehållet i rapporten ska anses 

vara insiderinformation. 


КІ 23.00 - telefonmöte (EdF, NBG, J!, GS, NR, DW) där utkast till 
kommunikation/pressmeddelande och rapportutkastet och dess 
innehåll diskuterades. Det konstaterades bland annat att 
huvudslutsatserna var publicerade genom artikel den 26 mars. 


EdF mailar RG för att lyfta frågan om ev insiderhantering ау EG- — } 


rapporten. 
Mail om ev 


Insiderhantering EG ra 


Fortsatta diskussioner avseende förslag till 
kommunikation/pressmeddelande och rapportutkastet och dess 


innehåll. 


2019-04-03 


På kvällen den 3 april får EdF vetskap om en annan rapport — 
nedan kallad BDO-rapporten - genom telefonsamtal med Ingrid 
Harbo, CAE, (IH)). Denna rapport är daterad 20 september 2018 
och är upprättad av bankens compliancefunktion. Rapporten har 
delgetts vd, CRO, Head of Baltic Banking, och Head of CEO Office (i | 
egenskap av Specially Appointed Executive for AML of Swedbank 
AB). Påskrift på rapporten: ” Internal Memo Confidential — not to 
be spread to anyone without the express consent of the CEO of 
Swedbank AB (publ). De “findings” som framgar av rapporten 
rapporterades aldrig vidare till bankens styrelse. Denna rapport 
hade med mycket hög sannolikhet bedömts мага _ 


180920 Exposure 


КІ 21.30 - telefonmöte (EdF, NBG, JJ, GS, NR, DW). | 
| 
| Final (2).docx 
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2019-04-04 


2019-04-05 


2019-04- 
10--11 


| insiderinformation om den bedömts rättidigt i september 2018. 


KI 10.30 får Anders Karlsson och Ulrika Francke vetskap om 
innehållet i BDO-rapporten. Hanteringen av rapporten ur 
insiderperspektiv diskuterades mellan IH, EdF, Anders Karlsson (vd) | 
och Ulrika Francke (vice ordförande i styrelsen). 


КІ 15.30 diskuteras insideraspekten med JJ och GS, GDA, vid ett 
telefonmóte. Det óverenskoms på detta möte att även försöka 
täcka in innehållet i BDO-rapporten i det tänkta pressmeddelandet. 


КІ 23.00 diskuteras problematiken med de båda rapporterna på ett | 
nytt telefonmóte (EdF, JJ, GS, samt Clifford Chance — Daniel Silver 
m.fl.). Riskerna med att öppna insiderlista så långt i efterhand samt 
ta beslut att offentliggöra eller skjuta upp offentliggörandet, 
diskuterades ånyo. Det tänkta pressmeddelandet, som var tänkt 
att mitigera riskerna med att ingen av rapporterna hade kunnat 
hanteras enligt ordinarie process för insiderhantering, diskuterades 
också. GDA åtog sig att ta fram ett utkast till sådant 
pressmeddelande, samt stämma av detta med Clifford Chance. 


På ovan telefonmöten diskuterades om innehållet i rapporten ska 
ses som insiderinformation. Diskuterades vidare att ta fram 
pressmeddelande och redogöra för/kommentera uppgifterna i 
rapporten samt offentliggöra uppgifter som inte framgick av 
artikeln den 26 mars. Informationen i pressmeddelandet syftade | 
bland annat till att mitigera vissa framtida risker för bankens del 
samt risken med att varken EG-rapporten eller BDO-rapporten 

hade kunnat bedömas utifrån MAR/insider perspektiv i rätt tid. Det 
utkast som togs fram förankrades genom GDAs försorg med 

Clifford Chance. 


| Pressmeddelande och kommunikationsplan upprättas under 10:e 


och 11:e april I olika versioner för offentliggörande av 
organisationsförändring och förändringar i bankens ledning och för 
att mitigera MAR-relaterade risker 


— 


DOK-#3345494-v4-Ev 
erest - Memo consequ 


Mailväxling ang 
Proposed Media state) 


190403-PM om 
rapporten (v3).docx 


Mailväxling Everest - 
MAR konsekvenser.do 


0405 - Angående 
medieuppgifter om Ide 


Mallvaxiing om PRM 
ang medieuppgifter or 


190410-Communicati 
on plan (v3).docx 


190410-Communicati 
on plan (v5).docx 


190410-Соттипісан 
on plan (v7).docx 


190411-Communicati 
on plan (v10).docx 
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2019-04-11 | Vid möte kl 18.30 den 11 april hos AK (tillsammans med Kreab, 

GFR, GK och Åsa A) överenskoms att avvakta med pressmedd till | 
01 rapporten, 24/4. "v 
2019-04-23 | EdF skickar synpunkter pá kommunikationsplan och VD-ord till GFR | 


Communication plan 
(v18).docx m и EdF.dc 


| CEO statement Qi 
2019 ver 11.doox mu 


2019-04-25 | Pressmeddelande går ut КІ 07.00 om organisatlonsfórándring och 
förändringar i Swedbanks ledning 
Communication plan 
(v23).docx 
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-----Original Message----- 

From: Cecilia Hernqvist 

Sent: den 19 februari 2019 18:24 

To: Eva De Falck 

Cc: Gabriel Francke Rodau; Nene Bjerström Galvan 
Subject: Re: RE: RE: 


Det är det som är bedömningen det Nenne ska skriva, eller talar vi om varandra Eva? 
Ringer dig imorgon om detta 
Skickat från min iPhone 


> 19 feb. 2019 kl. 14:17 skrev Eva De Falck <eva.de-falck@swedbank.com>: 

> 

> Ok, jag uppfattade att du ändå ville ha en bedömning av om detta är insiderinfo (jag vet ju inte lika 
mycket som du och Gabriel). 

> Men då dokumenterar vi Internt att vi inte öppnar lista på de grunder du nämnde för Nene och nöjer 
oss så då. 

> 

> Ha det bra i Oslol 

> Mvh 

> Eva 

> 

> -—-Orlginal Message----- 

> From: Cecilia Hernqvist 

> Sent: den 19 februari 2019 13:53 

> To: Eva De Falck 

>Сс: Gabriel Francke Rodau 

> Subject: Re: RE: 

> 

> Det viktiga är att det inte är insider, enligt min bästa bedömning och vi har dessutom diskuterat denna 
fråga tidigare Eva. 

> 

> Hur som jag har talat m Nenne, han kommer dokumentera det o det var det jag var ute efter för 
bankens skulll 

> 

> Trevlig em hälsas från Oslo 

> 

> Skickat från min iPhone 

> 

>> 19 feb. 2019 КІ. 10:34 skrev Eva De Falck <eva.de-falckQswedbank.com>: 

>> 

>> Listan omfattar ju enbart "interna", men det rör сір alltså от så pass många? 

>> | så fall kan Jag tycka att det är meningslösta att ta upp det för beslut - eller vill ni ändå att vi 
protokollför detta? 

>> 

>> Mvh 
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>> Eva 

>> 

>> -----Original Message----- 

>> From: Gabriel Francke Rodau 

>> Sent: den 19 februari 2019 10:30 

>> To: Eva De Falck 

>> Cc: Cecilia Hernqvist 

>> Subject: RE: 

>> 

>> Okej, be Nene kontakta mig. 

>> 

>> Vi kan omöjligt upprätta en lista. Vi vet inte vilka som vet helt enkelt, Utanför var kontroll, 

>> 

>> Gabriel Francke Rodau 

>> Head of Group Communication 

>> Group Communication 

>> CEO Office 

>> 

>> Swedbank AB (publ) 

>> SE- 105 34 STOCKHOLM 

>> Dir: +46(0)8 58 59 21 07 

>> Mob: +46(0)70 144 89 66 

>> 

>> 

>>--- Original Message----- 

>> From: Eva De Falck 

>> Sent: den 19 februari 2019 10:24 

>> To: Gabriel Francke Rodau 

>> Cc: Cecilia Hernqvist 

>> Subject: RE: 

>> 

>> Men det sänds=blir offentligt imorgon, eller hur? 

>> Det blir i s f bara fram till kl 18 (Börsens stängning) imorgon som listan är öppen. Och vi måste då 
snabbt notifiera dem som finns på listan. 

>> Möjligen kan vi fatta ett beslut om att det inte går att öppna lista, eftersom det är för många/okänt 
antal internt som känner till det (det är ји dessa som mäste informeras om att de inte fär handla i våra 
instrument). 

>> 

>> Dessutom har vi ju informerat Fl, eller hur, så vi behöver inte öppna lista för deras skull s a s. 

>> 

>> Eftersom jag sitter i styrelsemöte hela dagen, så kan jag be Nene kontakta dig och Gregori och bilda 
sig en uppfattning och i s f förbereda protokoll och notifiering till dem som ska registreras på listan, Men 
då måste någon förse oss med de патп som ska upp på listan. 

>> 

>> Vad säger ni? 

>> 

>> Mvh 

>> Eva 
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>> -----Original Message----- 

>> From: Gabriel Francke Rodau 

>> Sent: den 19 februari 2019 10:16 

>> To: Eva De Falck 

>> Subject: RE: 

>> 

>> Förstår. 

>> 

>> Problemet är följande: 

>> 

>> - aktien kan eventuellt gå ner till följd av programmet, men det vet vi egentligen inte givet att vi inte 
vet hur det kommer se ut 

>> - är smått omöjligt att sätta upp insider-listan eftersom antalet människor som känner till är minst 100 
personer vid det här laget och utanför vår kontroll 

>> 

>> Så om protokoll snarare symboliskt för att visa att vi tagit ett beslut. 
>> 

>> Gabriel Francke Rodau 

>> Head of Group Communication 

>> Group Communication 

>> CEO Office 

>> 

>> Swedbank AB (publ) 

>> SE- 105 34 STOCKHOLM 

>> Dir: +46(0)8 58 59 21 07 

>> Mob: +46(0)70 144 89 66 

>> 


>> From: Eva De Falck 

>> Sent: den 19 februari 2019 10:14 
>> To: Gabriel Francke Rodau 

>> Subject: RE: 

>> 

>> Styrelsemöte fram till kl 15 (minst). 
>> Maila gärna - styrelseutbildning nu, så jag kan kolla mail! 
>> 

>> -----Original Message----- 

>> From: Gabriel Francke Rodau 

>> Sent: den 19 februari 2019 10:12 
>> To: Eva De Falck; Cecilia Hernqvist 
>> Subject: RE: 

>> 

>> Jag ringer dig Eva. 

>> 

>> Gabriel Francke Rodau 

>> Head of Group Communication 

>> Group Communication 
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>> CEO Office 

>> 

>> Swedbank AB (publ) 

>> SE- 105 34 STOCKHOLM 

>> Dir: +46(0)8 58 59 21 07 

>> Mob: +46(0)70 144 89 66 

>> 

>> 

>> -----Original Message----- 

>> From: Eva De Falck 

>> Sent: den 19 februari 2019 10:10 

>> To: Gabriel Francke Rodau; Cecilia Hernqvist 

>> Subject: RE: 

>> 

>> Hej, 

>> 

>> Beror ju lite på vad som framgår - och hur det tas emot. Det är väl nästan upp till Gregori och er att 
avgöra, som har större insyn, men vi kan absolut titta på det. 
>> Sänds imorgon, eller, så blir ju en kort lista i s f. 

>> Vilka ska i s f vara med på listan? (Förutom vi, Birgitte, Gregori ....) 
>> 

>> Mvh 

>> Eva 

>> 


>> From: Gabriel Francke Rodau 

>> Sent: den 19 februari 2019 09:37 
>> To: Cecilla Hernqvist; Eva De Falck 
>> Subject: RE: 

>> 

>> Gregori hade samma tanke igår efter ägarmötet, men jag tycker svårbedömt. Eva, vad säger du? 
>> 

>> Gabriel Francke Rodau 

>> Head of Group Communication 
>> Group Communication 

>> CEO Office 

>> 

>> Swedbank AB (publ) 

>> SE- 105 34 STOCKHOLM 

>> Dir: +46(0)8 58 59 21 07 

>> Mob: +46(0)70 144 89 66 

>> 

>> -----Original Message----- 

>> From: Cecilia Hernqvist 

>> Sent: den 19 februari 2019 09:25 
>> To: Eva De Falck; Gabriel Francke Rodau 
>> Subject: 

>> 
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>> Har ni funderat på от UG Кап vara Insider info? Tror inte det men пі kanske behöver göra еп 
bedömning o skriva ett protokoll? 

>> 

>> Skickat från min iPhone 
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Ема De Falck 

V El ЖЕ Е —— — AeGNI 
From: Eva De Falck 

Sent: den 20 februari 2019 21:15 

To: Gregori Karamouzis 

Subject: FW: RE: 


Hej Gregori, 


Här ser du hela slingan. I första mailet ber jag Nene att även kontakta dig - sedan försiggick tydligen konversationen 
enbart mellan Cecilia, Gabriel och Nene. Jag skriver också att jag sitter I styrelsemöte och inte kan tala i telefon själv. 


I slingan framgår också att jag delade uppfattningen att vi skulle öppna lista avseende dem som hade den 
bakomliggande informationen. Vi hade t o m listan klar för utskick, men stoppade den för att Cecilia tyckte det var 
fel. Nedan ser du att Cecilia inte tyckte det var en bra idé att öppna lista avseende dem som hade bakomliggande 
info. Cecilia ringde sedan Nene och Nene skickade mig ett sms efter samtalet, som јад har vidarebefordrat till dig 
som sms. I detta framgår varför Cecilia inte tyckte att lista skulle öppnas. 


Eftersom varken jag eller Nene visste vilken den bakomliggande informationen var, férlitade vi oss pa Cecilia 
(eftersom hon visste vilken information det rörde sig om). 


Vad gäller protokollet har Nene skickat det till Cecilia för synpunkter. 
Du far det så snart jag far tillbaks det. 


Mvh 
Eva 


From: Cecilia Hernqvist 

Sent: den 19 februari 2019 12:41 

To: Eva De Falck 

Cc: Gabriel Francke Rodau; Nene Bjerström Galvan 
Subject: Re: RE: 


Nej det känns inte bra, ringer er sen 
Skickat fran min iPhone 


> 19 feb. 2019 kl. 12:31 skrev Eva De Falck <eva.de-falck@swedbank.com>: 
> 

> Later bra! 

> 

> Mvh 

> Eva 

> 

> -----Original Message----- 

> From: Gabriel Francke Rodau 

> Sent: den 19 februari 2019 12:28 
> To: Eva De Falck; Cecilia Hernqvist 
> Cc: Nene Bjerström Galvan 

> Subject: RE: 

> 
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> Jag har pratat med Nene och vi hittat en bra lösning. Vi öppnar en lista, MEN har bara med personer som de facto 
sett den bakomliggande informationen/fakta som vi fått fran Uppdrag Granskning. 
> 

> På den listan ar det i så fall bara följande som ska vara med (någon mer??): 
> 

> - Birgitte B 

> - Ragnar g 

> - Charlotte E 

> - Cecilia H 

> - Josefine U 

> - Johan L 

> - Gabriel FR 

> 

> För det är ju den informationen, snarare än det faktum att Uppdrag granskning kommer handla om 
penningtvätt/Swedbank som kan vara kurspåverkande. 

> 

> Gabriel 

> 

> 

> Gabriel Francke Rodau 

> Head of Group Communication 

> Group Communication 

> CEO Office 

> 

> Swedbank AB (publ) 

> SE- 105 34 STOCKHOLM 

> Dir: +46(0)8 58 59 21 07 

> Mob: +46(0)70 144 89 66 

> 

> 

> -----Original Message----- 

> From: Eva De Falck 

> Sent: den 19 februari 2019 10:40 

> To: Gabriel Francke Rodau 

> Cc: Cecilia Hernqvist 

> Subject: RE: 

> 

> Har messat Nene (som är på sportlov) och ber honom kontakta dig, Gabriel. 
> Mvh 

> Eva 


> From: Gabriel Francke Rodau 

> Sent: den 19 februari 2019 10:39 

> To: Eva De Falck 

> Cc: Cecilia Hernqvist 

> Subject: RE: 

> 

> Vi håller bla på att skicka ut info till alla chefer inom SBV och kommer imorgon (innan programmet sänds) ta upp 
ämnet på Banknytt. 

> 

> För min del inte nödvändigt protkollföra, men jag är inte jurist :-) 
> 

> 

> 

> Gabriel Francke Rodau 
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> Head of Group Communication 
> Group Communication 

> CEO Office 

> 

> Swedbank AB (publ) 

> SE- 105 34 STOCKHOLM 

> Dir: +46(0)8 58 59 21 07 

> Mob: +46(0)70 144 89 66 

> 

> 

>----Огіріпа! Message----- 

> From: Eva De Falck 

> Sent: den 19 februari 2019 10:34 
> To: Gabriel Francke Rodau 

> Cc: Cecilia Hernqvist 

> Subject: RE: 

> 


> Listan omfattar ju enbart "interna", men det rör sig alltså om så pass många? 
> I så fall kan jag tycka att det är meningslösta att ta upp det för beslut - eller vill ni ändå att vi protokollför detta? 


> 

> Mvh 

> Eva 

> 

> --—Original Message----- 

> From: Gabriel Francke Rodau 
> Sent: den 19 februari 2019 10:30 
» To: Eva De Falck 

» Cc: Cecilia Hernqvist 

» Subject: RE: 

> 

> Okej, be Nene kontakta mig. 
> 


> Vi kan omöjligt upprätta en lista. Vi vet inte vilka som vet helt enkelt. Utanför vår kontroll. 


> 

> Gabriel Francke Rodau 

> Head of Group Communication 
> Group Communication 

> CEO Office 

> 

> Swedbank AB (publ) 

> SE- 105 34 STOCKHOLM 

> Dir: +46(0)8 58 59 21 07 

> Mob: +46(0)70 144 89 66 


> From: Eva De Falck 

> Sent: den 19 februari 2019 10:24 

> To: Gabriel Francke Rodau 

> Cc: Cecilia Hernqvist 

> Subject: RE: 

> 

> Men det sänds=blir offentligt imorgon, eller hur? 
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> Det blir i s f bara fram till kl 18 (Bórsens stängning) imorgon som listan аг öppen. Och vi måste da snabbt notifiera 


dem som finns pa listan. 
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> Möjligen Кап vi fatta ett beslut от att det inte går att öppna lista, eftersom det är för många/okänt antal internt 
som känner till det (det är ju dessa som måste informeras om att de inte får handla i våra instrument). 

> 

> Dessutom har vi ju informerat Fl, eller hur, så vi behöver inte öppna lista för deras skull s a s. 

> 

> Eftersom jag sitter i styrelsemöte hela dagen, så kan jag be Nene kontakta dig och Gregori och bilda sig en 
uppfattning och i s f förbereda protokoll och notifiering till dem som ska registreras på listan, Men då måste någon 
förse oss med de namn som ska upp på listan. 

> 

> Vad säger ni? 

> 

> Mvh 

> Eva 

> -----Original Message—— 

> From: Gabriel Francke Rodau 

> Sent: den 19 februari 2019 10:16 

> To: Eva De Falck 

> Subject: RE: 

> 

> Förstår. 

> 

> Problemet är följande: 

> 

> - aktien kan eventuellt gå ner till följd av programmet, men det vet vl egentligen inte givet att vi inte vet hur det 
kommer se ut 

> - är smått omöjligt att sätta upp insider-listan eftersom antalet människor som känner till är minst 100 personer 
vid det här laget och utanför vår kontroll 

> 

> Så om protokoll snarare symboliskt för att visa att vi tagit ett beslut. 

> 

> Gabriel Francke Rodau 

> Head of Group Communication 

> Group Communication 

> CEO Office 

> 

> Swedbank AB (publ) 

> SE- 105 34 STOCKHOLM 

> Dir: +46(0)8 58 59 21 07 

> Mob: +46(0)70 144 89 66 


> From: Eva De Falck 

> Sent: den 19 februari 2019 10:14 

> To: Gabriel Francke Rodau 

> Subject: RE: 

> 

> Styrelsemöte fram till kl 15 (minst). 

> Maila gärna - styrelseutbildning nu, så jag kan kolla maill 


> From: Gabriel Francke Rodau 

> Sent: den 19 februari 2019 10:12 
> To: Eva De Falck; Cecilia Hernqvist 
> Subject: RE: 

> 
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> Jag ringer dig Eva. 

> 

> Gabriel Francke Rodau 

> Head of Group Communication 
> Group Communication 

> CEO Office 

> 

> Swedbank AB (publ) 

> 5Е- 105 34 STOCKHOLM 

> Dir: +46(0)8 58 59 21 07 

> Mob: +46(0)70 144 89 66 

> 

> 

> -----Original Message-—-- 

> From: Eva De Falck 

> Sent: den 19 februari 2019 10:10 


> To: Gabriel Francke Rodau; Cecilia Hernqvist 


» Subject: RE: 
> 

> Hej, 

> 


> Beror ju lite på vad som framgår - och hur det tas emot. Det är väl nästan upp till Gregori och er att avgöra, som 
har större insyn, men vi kan absolut titta på det. 

> Sänds imorgon, eller, så blir ju en kort lista 1$ f. 

> Vilka ska i s f vara med på listan? (Förutom vi, Birgitte, Gregori ....) 


> 

> Mvh 

> Eva 

> 

> — Original Message----- 

> From: Gabriel Francke Rodau 

> Sent: den 19 februarl 2019 09:37 


> To: Cecilia Hernqvist; Eva De Falck 


> Subject: RE: 
> 


> Gregori hade samma tanke igår efter ägarmötet, men jag tycker svårbedömt. Eva, vad säger du? 


> 

> Gabriel Francke Rodau 

> Head of Group Communication 
> Group Communication 

> CEO Office 

> 

> Swedbank AB (publ) 

> SE- 105 34 STOCKHOLM 

> Dir: +46(0)8 58 59 21 07 

> Mob: +46(0)70 144 89 66 

> 

> -----Original Message----- 

> From: Cecilia Hernqvist 

> Sent: den 19 februari 2019 09:25 


> To: Eva De Falck; Gabriel Francke Rodau 


> Subject: 
> 


> Har ni funderat på om UG kan vara insider info? Tror inte det men ni kanske behöver göra en bedömning o skriva 


ett protokoll? 
> 
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> Skickat från тіп iPhone 
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Nene Bjerström Galvan 


Specification 
Council on Managing of Inside Information 


Minutes 
Per Capsulam 


Securlty 
Confidential 


Present 
Eva de Falck (Chair), Gabriel Francke Rodau 
Absent 


Anders Karlsson, Gregor] Karamouzis 


Attending | 


Meeting papers that has been circulated to tha members prior to the meeting are incorporated by 
reference and referred to as the "Papers" at each relevant item below. Any additional 
documentation circulated or presented at the meeting Is referred to as an appendix at each Кет 
below and incorporated by reference, 


§1 Opening of meeting 
The Chalr opened the meeting. 


§2 Approval of previous minutes 


N/A. 


83 Information regarding Swedbank Estonia's work to prevent money laundry etc. 


The Swedish television program Uppdrag Granskning ("UG") is investigating how 
Swedbank Estonia has been working to prevent money laundering and if the Estonlan 
branch has been used for money laundering. The program will be alred in Swedish 
television on 20 th February at 8 pm. In connection with the investigation the bank has 
received certain Information from UG. 


The question has been raised if Information received from UG or the fact that UG Is 
investigating Swedbank's Estonian operations from a money laundering perspective as 
such, should be considered as inside Information. 


According to the CMI the information Is to brief and limited for the CMI to be able to make a 


proper assessment. Mo 
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Due to above the CMI's assessment at this stage, after consulting Swedbank’s Chief 
Compliance Officer, is that information received from UG and the fact that UG is 
investigating Swedbank's Estonian branch from a money laundering perspective is not 
likely to have a significant effect on the price of Swedbank's shares and therefore not 
deemed to be insider informatlon. 


At the minutes: Checked by: 


“Айға, д. Eva De Falck 
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Addendum 


2019-02-21 


Swedbank € 


Addendum to Minutes 2019-02-20 "Information regarding Swedbank Estonla’s work 
to prevent money laundry etc." 


Swedbank has recelved informatlon from UG in accordance with the following timeline: 


e 11 February, 12:00; Swedbank Is contacted by Axel Gordh Humlesjö at UG, who 
asks for an interview with Birgitte Bonnesen. 

• 13 February, 14:30; Axel Gordh Humlesjö e-mails the bank's communication 
department with certaln limited information prior to the Interview with Gabriel 
Francke Rodau on 15 February, ae per Appendix 1. 

‚ 15 February, 10:00; UG Interviews Gabriel Francke Rodau. 

• 18 February, 07:00; Axel Gardh Humlesjö e-mails information that another TV show 
by UG will be aired with focus оп Swedbank, Appendix 2. 


It Is noted that the CMI did not have access to above and attached information until 21 
February. 


It le further noted that the information provided to the bank by UG is brief, limited and 
imprecise, Details euch as customer names and time data are missing. UG has refused to 
provide any additional information, aithough the bank has requested it. The customers 
referred to in UG's e-mall of 13 February are unnamed. It 18 unknown what the amount of 
SEK 40bn relates to and to which period. The four customers named іп UG's e-mail of 18 
February have been subject to internal searches but all but one needs further searches to 
get a better understanding. A disclosure of the imprecise information received from UG 
would not make any sense and help the market. iA 
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Appendix 1 
Mejl 13 februari 


"UPPDRAG GRANSKNING, SVT 1 - 20/2 2019 

Birgitte Bonnesen, och Swedbank, har vid många tillfällen, och på olika sätt under det senaste 
halvåret förklarat att Swedbank inte har haft samma problem som Danske Bank I Baltikum, 
avseende misstänkt penningtvätt. 


Sverige Television har, som part I ett Internationellt samarbete, tagit del av transaktionsdata 
gällande flera svenska storbanker, däribland Swedbank. 


Uppdrag granskning har kartlagt delar av transaktionsunderlaget och kommer till följande 
slutsatser: 


1) Swedbank har, likt Danske Bank, haft en stor non-resident-portfól| (och även en HRNR-grupp). 


2) Många dessa kontohavare (NR) saknar synlig affärsverksamhet. 


3) Många av Swedbanks kontohavare (NR), eller deras motparter, är skrivna på adresser som 
förekommer I rapporter kring korruption och penningtvätt. Över 1200 kontohavare (I Swedbank 
eller motparter I annan bank) delar adress med andra bolag. 


4) Ett flertal kontahavare I Swedbank, eller deras motparter I annan bank, finns omnämnda i 
tidigare penningtvättshärvor. 


5) Av de specialstuderade kontohavare (NR)/motparter ser vi tecken på falska årsredovisningar, 
samt transaktioner till vilande bolag. 


6) Flera av de mest väldokumenterade målvakterna finns i bolag som har konto I 
Swedbank/Swedbanke motparter. 


7) Pengar från den sk. "Magnitsky-affáren", det väldokumenterade skattebedrageriet i Ryssland, 
slussas іп | Swedbank. 


8) UG har granskat de 50 kontohavare | Swedbank som drar på slg flest varningsflaggor för 
misstänkt penningtvätt. Dessa 50 misstänkta konton omsätter motsvarande 40 miljarder SEK. 


Sverlges Television, Uppdrag granskning, vill intervjua VD Birgitte Bonnesen om slutsatserna i 
маг kartläggning. Senaste fredag eftermiddag (15/2) kommer vl till Swedbank för att genomföra 


Intervjun." wA 
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Appendix 2 
Меј! 18 februari 


"Наг kommer information om nästa del ам granskningen i маг serie om penningtvätt I Baltikum. 
Detta program sänds den 27 februari 2019 och ytterligare dalar av granskningen kommer också 
publiceras på svt.se 


Vi är medvetna om att banksekretessen gör det svårt för er att kommentera alla detaljer i enskilda 
fall men det är viktigt att ni får ta del av den information som är relevant för ert gensvar. 


Bakgrund: 


Uppdrag granskning har, som vl förklarat tidigare, utgått från samma metoder вот den danska 
advokatfirman rörande Danske Bank, men Istället tittat på Swedbanks kunder. När vi letar efter 
högriskkunder hittar vi bolag som har bas I kända offshore jurlediktioner, och sammanräknat 
uppgår era non-residentkunder till över 1000 (fram till 2015 då Danske Bank stänger sin NR- | 
portfölj). 


Med utgångspunkt från de varningsflaggor vi letat efter har vl specialgranskat de 50 kunder som 
dragit på slg flest riskindikatorer | Swedbank, respektive Danske bank. Underlaget från Око Bank 
analyseras fortfarande och kommer att publiceras senare I vår. 


Vi har med anledning av detta följande frågor: 
Frågor: 
1) Danske bank får av myndigheterna frågor gällande sin högriskgrupp: 


"The report from Group Compliance & AML also mentioned the bank's reply іп 2012 to the Danish 
FSA "regarding the high market share of high risk сизјотег5 (Рапзке Bank-rapporten 5.45) | 


Наг motsvarande frågor – om andelen hégriskkunder - ställts till Swedbank i Sverige eller de tre 
baltiska länderna? I så fall när och av vem? | 


2) Nar vl analyserar transaktionsmönster och ägande (i de fall det är möjligt) ser vi en rad 
"kluster", Vi har studerat några av dessa t ex, eftersom de 
utmärker sig avseende omsättning. 


Dessa två kluster har en mängd konton I både Danske bank och Swedbank. 


Har nt identifierat misstänkt penningtvätt kopplat till dessa två bolagestrukturer? I sà fall när? 
Vilka åtgärder har ni vidtagit? 


| vår research ser vi att en rad av bolagen Кап misstänktas för penningtvätt. Många 
varningsflaggor kommer upp såsom målvakter, skatteparadis, ökända advokatbyråer, 
gemensamma adresser etc. Ändå fortsätter pengar slussas år efter år, Varför har inte banken 


agerat? 


3) Ett av de bolag = omsätter mest i relation till Danske Bank är 

På många av de omfattande transfererlngarna.. mellan tår det 
I vår data endast "Loan agreement” och ett datum, och samma beskrivning återkommer för 
väldigt många transaktioner. Finns det hos Swedbank underliggande dokumentation som styrker 


dessa stora återkommande överföringar? VM 
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4) UBO bakorn Ш enligt vår kartläggning as Kande 
Swedbank till att ШЕ: den egentliga ägaren av i banken? 
S i pekas ! vår research ut (av åklagare вот utrett organiserad brottslighet) | 


som högrisk-kund, med starka kopplingar till organiserad brottelighet och korruption. Vad är ег 
kommentar till det? | 


6) Vi har specialstuderat transaktioner som gått mellan Swedbank och Danske bank från kunder 
med bolag I England. Vi kan då se en rad misstänkta fall av penningtvätt. Exempelvis 

transaktioner till icke-aktiva bolag har genomförts och många av bolagen delar adresser och kan 
kopplas till tidigare penningtvättshärvor. Hur ser ni på det? | 


ПАН (med tillhörande kluster av bolag) fortfarande kunder | 


Swedbank? 


Uppgifterna ovan kommer att publiceras Inom kort varför vi hoppas kunna få ett snabbt svar, 


Med vänlig hälsning x 


Axel" 
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From: Eva De Falck 

Sent: den 1 mars 2019 11:12 
To: Ragnar Gustavii 
Subject: CMI 


Hej Ragnar, 


Beträffande insiderkommittén, CMI har funderat ytterligare efter vårt samtal igår och skulle vilja kliva av 
som Chair av följande skäl: 


1. Jag behöver fokusera på mitigerande åtgärder och krishantering gällande AGM, Baltikum, extern 
och intern kommunikation, styrelsehantering mm. Dessutom måste jag se till att verksamheten 
fungerar och att Group Legal kan fortsätta supportera affären, som ju måste rulla på. Till skillnad 
från Compliance kan vi ju inte dedikera en massa jurister till detta — vi är ju i första linjen och 
affären måste ju rulla vidare. 

2. Dessutom hamnar jag i en tydlig intressekonflikt när jag å ena sidan jobbar i linjen med 
riskmitigerande åtgärder och 8 andra sidan ska fatta ett netutralt och objektivt beslut, utifrån 
risken för sanktioner och disciplinåtgärder för banken. Vi har ju inga kollektiva beslut i banken 
och den som fattar beslutet borde enligt min mening sitta på armlängds avstånd till affären och 
inte mitt i. (Risk, GIA el dyl. Även vissa funktioner i CFO-Office är tänkbara). I normalfallet när det 
handlar om att öppna insiderlistor inför kvartalsbokslut eller M&A transaktioner blir inte detta 
något problem, men det accentueras i en krissituation som denna. Jag talade även med Johan 
Josjö, GDA, om detta igår kväll och han höll med om att detta är en tydlig Intressekonflikt och 
inte alls optimalt. OBSI Jag tycker att en jurist med rätt kompetens ska vara med i CMI, alt 
adjungerad, men inte vara Chair. 

3, Johan Josjö var även enig med mig om att det krävs att alla strömmar eskalerar händelser till CMI 
om processen ska fungera. Jag kan (och hinner) inte gå runt och fråga flera gånger om dagen om 
något har hänt, utan omständigheter som kommer till bankens kännedom och som kan vara 
kursdrivande måste eskaleras och loggas samt och ev bedömas och protokollning. 

Utifrån risken för disciplinåtgärder är den relevanta tidpunkten när banken fått vetskap om 
omständigheten och inte när CMI har fått veta. Jag tycker inte det är acceptabelt att Compliance 
säger att de inte har tid att eskaleral 


Låt oss prata vidare om detta i nästa vecka. Jag har lite idéer om hur det kan lösas också. 


Mvh 

Eva 

Med vänlig hälsning/Kind regards 
Eva C. de Falck 


Chefsjurist / Chief Legal Officer 
Head of Group Legal/Secretary of the Board 


Swedbank (publ) AB 

105 34 Stockholm 

Dir +46 8 585 935 07 

Mob +46 72 733 48 47 

Gen +46 8 585 900 00 

Email eva.de-falck@swedbank.com 
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From: Eva De Falck 

Sent: den 25 februari 2019 13:10 
To: DL.GEC 

Subject: Important information 


SWEDISH 

Nedanstående information skickades fredagen den 22 Februari till GEC-ledamöter och andra 
anställda med insyn i pågående AML-ärende. 

Meddelandet ska skickas vidare till personer som har tillgång till information och har insyn i frågorna. 
Observera att det är varje GEC-ledamots ansvar att se till att meddelandet når dem det berör i 
respektive organisation. Varje GEC-ledamot ansvarar också för att dokumentera vilka i respektive 
organisationen som har fått meddelandet. 

Vänligen notera också att de som har tillgång till kundinformation omfattas av banksekretessen, 
vilket innebär att sådan information inte får obehörigen röjas. 


ENGLISH 

The information below was circulated on Friday 22 February to GEC-members and others with insight 
into the current AML matter. 

The message shall be forwarded to employees with information and insight into the matter. Please 
be aware that it is the responsibility of every GEC-member to make sure that the message reaches 
the relevant employees in your respective units. Every GEC member is also responsible for keeping a 
log over employees in respective unit who have received the message. 

Please also remember that employees who have access to customer information are always bound 
by the banking secrecy, meaning that such information may not be disclosed. 


Information sent to GEC-members on 22 February: 


SWEDISH 

Vi har ännu Inte formellt öppnat någon insider-lista, men på grund av det känsliga läget vad gäller 
informationen runt Uppdrag Gransking, uppmanas ni att tills vidare inte handla med Swedbank- 
instrument/aktier. Detta för att dels begränsa eventuell kritik för det fall det i ett senare skede skulle 
ifrågasättas varför vi inte hade öppnat en insiderlista och dels för att det kan bli aktuellt att med kort 
varsel öppna en insiderlista om ny information framkommer. 


ENGLISH 

We have still not formally opened an Insider list, but due to the sensitive situation regarding the 
information from the TV show “Uppdrag Granskning”, you are hereby urged not to trade in 
Swedbank instruments/shares for the time being. The reason for this is partly to limit possible 
criticism at a later stage, in case it should be questioned why we have not opened an insider list, and 
partly because it can be necessary to open an insider list with very short notice, In case new 
information should emerge. 


Med vänlig hálsning/ Kind regards 
Eva C. de Falck 


Swedbank > 


Chefsjurist/ Chief Legal Officer 
Head of Legal/Secretary of the Board 


Swedbank (publ) AB 
105 34 Stockholm 
Dir +46 8 585 935 07 
Mob +46 72 733 48 47 
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Gen +46 8 585 900 00 
Email eva.de-falck@swedbank.com 
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Swedbank = Minutes 


Per Capsulam 


Author Date and Time Page 
Nene Bjerström Galvan 2019-03-26, 13:00 

Specification Securlty 

Council on Managing of Inside Information Confidential 


Present 
Eva de Falck (Chair), Gabriel Francke Rodau, Gregori Karamouzis 


Absent 


Anders Karlsson 


Attending 


Meeting papers that has been circulated to the members prior to the meeting are incorporated by 
reference and referred to as the "Papers" at each relevant item below. Any additional 
documentation circulated or presented at the meeting is referred to as an appendix at each item 
below and incorporated by reference. 


§1 Opening of meeting 


The Chair opened the meeting. 


§2 Approval of previous minutes 


N/A. 


§3 Information regarding article to be published by the television program Uppdrag 
Granskning 


Earlier today the bank received an email from the Swedish television program Uppdrag 
Granskning ("UG") with a draft to an article to be published today. The article contained, for 
example, alleged quotes from a report written, on behalf of Swedbank, by the Norwegian 
lawyer Ehrling Grimstad. Any comment, from the bank, on the article and the alleged 
quotes should be sent to UG no later than 1 pm today. 


The CMI received an email with a copy of the draft article at 11.17. 


It was noted that the CMI did not have access to the alleged report, why it was not possible 
for the CMI to assess the correctness of the quotes. 
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Due to above the CMI concluded that it was not possible for the CMI to make a proper 
assessment of the content of the draft article from an insider perspective. 


At the minutes: Checked by: 


Nene Bjerström Galvan Eva De Falck. 
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From: Eva De Falck 

Sent: den 2 april 2019 14:17 

To: Anders Karlsson 

Subject: RE: Två frågor jag bebóver lyfta med dig 


Hej igen, 
Punkt 1. Ok. 


Punkt 3 får vi ta tag i när allt lugnat ned sig, men punkt 2 kommer jag att behöva lyfta igen, när vi 
kartlagt riskerna. 


Cecilia har sedan tidigare skjutit ut sig ur insider kommittén (2:a linjen) och jag tycker inte det kánns 
rätt att blanda in henne i detta, eftersom hon/Compliance sas är parti målet. 
Vi försöker hantera det från Legal. 


Mvh 
Eva 


From: Anders Karlsson 

Sent: den 2 april 2019 13:39 

To: Eva De Falck 

Subject: RE: Två frågor jag bebóver lyfta med dig 


Hej Eva, 


1. Det är väl styrelsens rätt att få ta del av den Informationen. De har fått den tidigare och vill se 
den Igen? Jag förstår inte riktigt hur det kan vara en fråga. 

2. Vi måste följa den governance vi har beslutat om. Därför är det väl lämpligt att du 
(tillsammans med Cecilia?) tar ett móte med GDA och tillsammans reder ut fakta och vilka 
alternativ vi har, och dárefter fattar vederbórligt beslut. 

3. Vad gäller CMI processen framgent, skriv gärna ihop ett förslag till ny process och låt oss titta 
på det. 


//Anders 


From: Eva De Falck 

Sent: den 2 april 2019 11:48 

To: Anders Karlsson 

Subject: Två frågor jag bebóver lyfta med dig 


Anders, 
Jag vet att du har en extrem press, men jag måste lyfta två frågor med dig: 


1. Magnus U har bett att få ut Compliance Q1 rapport 2016 som Viveka avlämnade. Denna 
rapport är omfattande och flaggar för en hel del brister v g AML i Baltic Banking. I en bilaga 
till rapporten adresseras en uppföljning av off-shore engagemang, eftersom styrelsen bett 
om en uppdatering m a a Panama Papers. Compliance råder banken att göra en cross 
check, samt säger att Compliance kommer att supportera och monitorera under Q3 2016 och 
återkomma med statusrapport till styrelsen. Detta följs dock aldrig upp – varken av 
Compliance eller styrelsen. Det talas också om stickprov som aldrig görs... Jag och Ingrid har 
bokat ett kort möte med dig idag om detta inför kvällens möte. Vi behöver ta ställning till 
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om Magnus/styrelsen ska få rapporten. Det är tydligt att det inte har följts upp av 
Compliance, men det slår Sven tillbaka på styrelsen som Inte har efterfrågat uppföljning. 


2. Den andra frågan rör ev insiderhantering av Grimstadrapporten. Den bedömningen borde 
naturligtvis ha gjorts redan i december, nar rapporten kom banken tillhanda och redan dar 
exponerar vi oss för en sanktionsrisk, Vi har nu att ta ställning till hur vi ska hantera den, nar 
den nu kommit till flera personers kännedom. Om vil kommer fram till att rapporten utgör 
insiderinformation, innebär det att vi måste fatta beslut om att offentliggöra de uppgifter i 
rapporten som kan antas vara kurspåverkande, alt. skjuta upp offentliggörandet. Om vi 
offentliggör uppgifterna, kan det innebära att vi äventyrar client priviliege.... 


Vad vi än beslutar ang rapporten innebär det att vi exponerar vi oss för risker som 
sanktionsavgifter från FI och sanktioner från börsen. Den allvarligaste sanktionen från 
börsen är att aktierna avnoteras, vilket förstås är en ren katastrof. Detta är en för stor 
fråga för att jag ska kunna hantera den ensam, eller inom ramen för CMI. Både 
banken och jag personligen exponeras för risker som är så stora att frågan måste 
lyftas till vd nivå. 


Jag har bett GDA att försöka kvantifiera riskerna I olika scenarlos och ge ett handfast 
råd om vilket agerande som innebär minst risk. Jag har också bett dem skissa på vad 
man (ur svensk legal synvinkel) skulle kunna kommunicera runt rapporten, för att 
uppfylla kravet på offentliggörande, samtidigt som vi inte säger sådant som ger 
ytterligare bad-will eller gör att vi bryter mot banksekretessen. En sådan 
kommunikation behöver självklart i nästa steg stämmas av med Clifford Chance. 


Vi behöver prata om denna fråga inom de närmaste dagarna och jag tror det vore 
lämpligt att ha ett möte med GDA så de får beskriva riskerna. 


Slutligen kan vi konstatera att var CMI funktion i banken 6 ht inte fungerar, eftersom 
den förutsätter att de som är representerade i kommittén har tillgång ШІ fakta om 
sådant som kan vara kurspåverkande. Så har inte varit fallet hos oss. 


Mvh 
Eva 


Med vänlig hälsning/Kind regards 
Eva С. de Falck 


Chefsjurist/Chief Legal Officer 
Head of Croup Legal/Secretary of the Board 


Swedbank (publ) AB 


105 34 Stockholm 


Dir +46 8 585 935 07 

Mob +46 72 733 48 47 

Gen +46 8 585 900 00 

Email eva.de-falck@swedbank.com 
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From: Eva De Falck 

Sent: den 3 april 2019 11:17 
To: Ragnar Gustavii 
Subject: CMI 


Hej Ragnar, 


Jag behöver lyfta frågan om ev insiderhantering av Grimstadrapporten med dig. Den 
bedömningen borde naturligtvis ha gjorts redan i december, nar rapporten kom banken tillhanda 
och redan i o m att det inte gjordes exponerar vi oss för en sanktionsrisk. Vi har nu att ta 
ställning till hur vi ska hantera rapporten, när den nu kommit till flera personers kännedom. Om 
vil kommer fram till att rapporten utgör insiderinformation, innebär det att vi måste fatta beslut 
om att offentliggöra de uppgifter i rapporten som kan antas vara kurspåverkande, alt. skjuta upp 
offentliggörandet. Omi vi offentliggör uppgifterna; kan det innebära att vi äventyrar client 
priviliege (advokatsekretessen), vilket kan fa bäring pa US Authorities.... 


Vad vi än beslutar ang rapporten medför det m a o att vi exponerar vi oss för risker som höga 
sanktionsavgifter från Fl och sanktioner från börsen. Den allvarligaste sanktionen från börsen är 
att aktierna avnoteras, vilket förstås är en ren katastrof, även om det inte är sannolikt. Detta är 
en för stor fråga för att jag ska kunna hantera den ensam, eller inom ramen för CMI (som inte 
längre existerar). Både banken och jag personligen exponeras för risker som är så stora att jag 
måste kunna bolla frågan med någon. Detta särskilt som vår CMI funktion i banken ö h t inte 
fungerar, eftersom den förutsätter att de som är representerade i kommittén har tillgång till 
fakta om sådant som kan vara kurspåverkande. Så har inte varit fallet hos oss. 


Anders vill inte längre delta i CMI p g a sin nya roll, vilket är förståeligt och Gabriel och Gregori 
har inte läst rapporten..... Tanken med CMI är ju att en bedömning ska göras av personer som är 
insatta i frågan och kan förutse hur kunder, finanser och investerare kan påverkas av 
informationen — inte att beslutet ska tas av mig personligen. 


Jag lyfter detta för att jag inte vill exponera banken för ytterligare risker, (inte för att vara 
besvárlig&). 


Jag har bett GDA att försöka kvantifiera riskerna i olika scenarios och ge ett handfast råd om 
vilket agerande som innebär minst risk. Jag har också bett dem skissa på vad man (ur svensk legal 
synvinkel) skulle kunna kommunicera runt rapporten, för att uppfylla kravet på offentliggörande, 
samtidigt som vi inte säger sådant som ger ytterligare bad-will eller gör att vi bryter mot 
advokatsekretessen. En sådan kommunikation behöver självklart i nästa steg stämmas av med 
Clifford Chance. 


Vi behöver prata om denna fråga inom de närmaste dagarna när jag har fått mer input från GDA. 


Mvh 
Eva 


Eva С. de Falck 


Chefsjurist/Chief Legal Officer 
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Head of Group Legal/Secretary of the Board 


Swedbank (publ) AB 
103 34 Stockholm 

Dir +46 8 585 935 07 
Mob +46 72 733 48 47 
Gen +46 8 585 900 00 
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Swedbank ф 


Follow up on Swedbank's risk exposure in relation to the investigation of ML issues in Danske 
Bank, Estonia 


Internal Memo/Confidential - not to be spread to anyone without the express consent of the 
CEO of Swedbank AB (publ) 


SUMMARY 


Background 


This memo is a follow up to previous reported risk exposure between Swedbank Baltic 
Banking (Swedbank) and Danske Bank Estonia (DBE)'. 


This memo is intended to give an overall oversight and insight into questionable 
transactions and to describe the risk related to Swedbank in relation to the investigation of 
money laundering (ML) issues in DBE - and especially customers and counterparties incl. 
their transactions that could be linked to the problems in DBE. It has not been possible at 
this stage to relate the numbers in this investigation to the numbers revealed In the DBE 
Report (defined below). 


cope of investigation who was involved 


Due to the big amount of data and transactions the investigations and analysis have been 
limited to (i) questionable transactions and parties, based on decided specific risk 
indicators that have been applied? during the period 2007-2015 and also thresholds for 
amounts. Hence, not all transactions between Swedbank and DBE have been analysed. 


Further, the portfolio investigation has been made using a risk based approach based on 
the decided risk indicators. Both former and current customers in Baltic Banking have been 
run against these risk indicators and grouped based on the perceived risk. A transaction- 
by-transaction approach has not been adopted in this phase of the investigation. This is 
due to time- and resource restraint, but also since this until now has not been deemed 
necessary”. Thus, some clients are only identified with one single transaction to/from these 
clients of DBE, while others have several transactions. _ 


1 Dated 2018-07-12 distributed only to a few internal stakeholders. 

2 The risk indicators used are (i) legal form": L.P, LP, LLP, LTD, LIMITED, LLC, INC, CORP, S.A. (more legal forms have later 
been detected as relevant, e.g., GMBH, A.G. A/S (Danish legal form), however transactions with these have not been 
significant in comparison to the others) (il) payment description: "loan", "refund", “repaid”, “return” (more payment details һауе 
been found as relevant, e.g., “consulting”, “corporate service", however transactions which includes these have not been 
significant in comparison to the others) (iii) currency: EUR (included EEK converted to EUR), USD have been used. Other 
currencies GBP, RUB and, CHF have been identifled but are not included in the amounts set out in this memo since they are 
deemed not to be significant and (iv) counterparty (clients of DBE). 

3 EUR 5000 for domestic payments and EUR 2500 for foreign payments. 

4 After having taken part of the "Report on the Non-resident Portfolio at Danske Bank's Estonian branch", made public 
2018-09-19, (the DBE Report) Compliance can conclude that this is the same approach that has been used by DBE. 


INTERNAL/CONFIDENTIAL 1 
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The fact that former ог current customers have been linked/involved in some suspicious 
payments does not necessarily imply that such payments or all of their payments were 
suspicious. 


The investigations and analysis have been done by Compliance, with the assistance of the 
external consultant BDO. 


A comprehensive way of describing the risk that Swedbank is exposed to when it comes to 
АМШСТЕ risks is by describing the networks and links that our clients are associated with, 
as is shown in certain examples in Appendix 1°. 


Key takeaways: 


The following most important takeaways are”: 


1) None of the entities that have been mentioned in media in the DBE case has been 
identified as customers of Swedbank based on transaction with DBE. (Only a few 
of the concerned DBE customers have so far been named in media.) 


2) The investigation shows, that approx. 3440 of Swedbank’s former and current 
customers have conducted transactions with counterparties of DBE and their 
networks, whereof approx. 2000’ are current customers. 


3) The turnover of identified questionable/suspicious clients and/or counterparties with 
transactions with DBE (the "Flow")? amounts to approx. EUR 3 200m and approx. 
USD 6 700m from 2007 till 2015, which comprises both former and current clients. 


4) 29 clients of Swedbank, of which 11 are still customers, have been identified as 
non-acceptable. They have been directly matched against the list of the Russian 
Laundromat companies published by the Organized Crime and Corruption 
Reporting Project (OCCRP). 163 counterparties, i.e. clients of DBE, on the same 
ОССЕР list have made transactions with Swedbank's customers, both former 
and current clients. 


5) 35 former clients of Swedbank, which all are UK registered LPs/LLPs, have 
performed transactions with clients of DBE. At least 17 of these former clients are 
controlled by some of the most infamous offshore companies and 
proxy/nominee directors linked to organized corruption and money 
laundering. In addition, these former LP/LLP clients are linked by transactions to 
other LP/LLP companies, some mentioned in relation to Magnistky, Azerbaijani 


5 Still in draft form 

8 Please note that the numbers of customers matched in different segments as well as stated amounts still are under validation 
by BDO, which means that there could be some changes in the data. 

T As set out in footnote 7, the data, which currently matches 1986 clients, is not fully confirmed. However, for the sake of 
simplicity the number 2000 is used throughout the memo at this point. 

s We аге for this purpose using the term as the DBE Report in order to be able to "compare". However, it should be noted that 
from what we understand the flow in the DBE Report is the total flow in DBE Estonia (not limited to flow to/from certain banks). 
However, the DBE Report only covers the so called Non-resident Portfolio and it is unclear what this precisely comprises. The 
investigation carried out by Compliance, could have identified customer and counterparties of DBE not covered by the Non- 
resident Portfolio. 
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Laundromat, Russian Laundromat, Deutsche Bank mirror trade and the problems 
related to DBE. 


6) At least 237 clients of Swedbank, mostly former, identified in the Flow have a 
positive match against the Investigative Consortium of Investigative Journalists 
(СЫ) database/lists ("ICIJ”), whereof at least 74 are linked to Mossack Fonseca 
(“МЕ”). 


7) Atleast 350 counterparties (i.e. clients of DBE) of Swedbank's customers have 
a positive match against ICIJ, whereof at least 100 are linked to MF. 
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1. Background 


DBE has repeatedly been accused of facilitating money laundering by the Danish business 
paper, Berlingske. The allegations have also been broadcasted by other media and 
organisations and the problems around DBE has also lead to investigations from authorities 
in Denmark and Estonia but also France; both in general as regards the bank as well as 
regarding possible criminal actions towards employees. The result of the investigation done 
by DBE was published in the DBE Report. 


It seems that Berlingske, as well as OCCRP, have access to internal documents and 
account statements from DBE customers. Based on those documents it has been concluded 
that accounts of non-resident companies (e.g., includes NZ, UK, PA, BZ, etc.) in DBE were 
used to transfer funds originating from several worldwide organized money laundering 
scheme, including the following (according to published info)’ : 


- Magnitsky - Transactions comprising DKK 28bn, during 2007-2015 connected to 
Russian tax fraud; named after the lawyer S Magnitsky, who died in a Russian prison 

- Moldova - Transactions comprising DKK 7bn, during 2011-2014 connected to tax fraud 
and corruption etc. involving Russian organized criminals 

- Azerbaijani Laundromat - Transactions comprising DKK 18bn, during 2012-2014 
connected to fraud and corruption also pointing at European officials and politicians 

- Russian Laundromat - Transactions value not revealed, but conducted during 2007- 
2015 connected to companies alleged controlled by the family of Putin and FSB. 

- Deutsche Bank Mirror Trading. 


It should also be noted that Bill Browder filed a report in July 2018 pointing at 26 former and 
current employees of DBE, accusing them of money laundering and other criminal activity. 
Ultimo July, the Estonian State Prosecutor's Office announced that criminal investigation has 
been started based on this report.'? The Danish Prosecutor's Office has informed about 
launching similar investigation in Denmark. The DBE Report also states that 42 employees 
and “agents” have been deemed to have been involved in some suspicious activity and 
where DBE is in the process of filing SARs to the Estonian FIU and further that they have 
reported 8 former employees directly to the Estonian police. 


This memo is intended to describe Swedbank’s risk as regards Swedbank's customers, their 
counterparties and their transactions which could be directly, or to some extent indirectly, 
linked to the problems in DBE and the customers in DBE that has been mentioned in the 
media, which are only a handful, while sources talks about several hundreds. 


12 прама b dematonaitvancdhshversion-an-oveviaveofthe-danska-bank-money-launderina-scandat . 

13 The Estonian media has also published an interview with an anonymous person who claimed that he/she is aware of 
practices that were used by the non-resident department of DBE. The source explained among other things how new clients 
were recruited and how the internal setup and ‘service packages’ made alleged money laundering іл DBE possible, including 
how special payments to employees was organized. 
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2. Scope of the investigation, available data and sources and who has been involved 


3, Customers, counterparties and the Flow | 
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4. Identified customers/transactions of non- acceptable and hig lon-acceptable and high high risk character — 
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Top transactions - off-boarded clients with special interest 
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Further, more detailed information of the existing customers connected to DBE is presented 
in Appendix 2. 
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A. Principles for risk appetite 


The proposed principles are as follows; 


r” 1 


B. Existing 2000 clients identified in the Flow - Monitoring and possible off-boarding 


11 
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Pressmeddelande 


5 april 2019 


Angående medieuppgifter om identifierade brister i regelefterlevnad i 
Swedbank AB 


I den senaste tidens medierapportering förekommer uppgifter om brister i Swedbanks 
regelefterlevnad när det gäller penningtvätt, bland annat i den sk Grimstadrapporten. 
Därför har banken med godkännande av styrelse och vd - och i samarbete med relevanta 
myndigheter - startat en bred granskning i både de svenska och baltiska verksamheterna. 


-Granskningen omfattar både efterlevnad av regelverk för att upptäcka och rapportera penningtvätt 
samt bankens styrningsprocesser. Granskningen genomförs i samarbete med relevanta 
myndigheter, säger Ragnar Gustavii, chef för VD-staben på Swedbank. 


Nedan utlåtande beskriver bankens pågående granskningsarbete 


Den senaste tidens uppgifter i media har indikerat att banken genom interna utredningar, har 
identifierat historiska brister i Swedbanks rutiner och kontroller för motverkan av penningtvätt i 
Baltikum. Vissa har utförts med externt stöd. 


Swedbanks arbete för att förbättra sina system och kontroller för regelefterlevnad omfattar 
pågående utvärderingar av effektivitet i systemen och kundförhållanden. Under de senaste åren har 
Swedbank genomfört flertalet granskningar av kundbas och övervakningsrutiner. Därigenom har 
Swedbank över tid identifierat historiska brister i rutiner och kontroller för att motverka penningtvätt. 
Till exempel har Swedbank identifierat att vissa kunder i Swedbanks baltiska verksamhet funnits 
med i listor över personer och företag som omnämnts i samband med tidigare misstänkta 
penningtvättsaffärer. Man har också sett att Swedbank Estland har ingått kundförhållanden trots att 
information verkar ha saknats om exempelvis företags verkliga ägare, pengars ursprung och vad 
affärsförbindelsers verkliga art och syfte varit. Det finns indikationer på att Swedbanks baltiska 
verksamhet underlåtit att utreda och rapportera misstänkta transaktioner och misstänkt beteende. 
Det finns också en risk att anställda i Swedbank Estland historiskt kan ha agerat i samarbete med 
kunder eller understött kunders misstänkta transaktioner och misstänkta beteende. 


Till följd av dessa utvärderingar har Swedbank över tid avslutat vissa kundförhållanden som 
identifierats innebära en risk som går utöver bankens risktolerans. Swedbank har också identifierat 
behov av förbättring och förstärkning i system och kontroller för att motverka penningtvätt. 


Dessa interna utredningar rörande historisk regelefterlevnad har varit en del av Swedbanks 
ordinarie arbete för att motverka penningtvätt. Vissa utredningar pågår fortfarande och finns i 
nuläget endast i utkastform. Vissa har varit begränsade i omfång och hade specifika syften och mål. 
Enskilt ger utredningarna inte en fullständig bild av de historiska eller nuvarande omständigheterna 
för bankens arbete mot penningtvätt. Detta gäller bland annat rapporten ”Draft Preliminary Status 
Report on AML”, vilken har upprättats av bankens externa ombud Erling Grimstad och omnämnts i 
media. 


Swedbank främjar en sund och hållbar ekonomi för de många människorna, hushållen och förelagen. Som en ledande bank på hommamarknaderna Sverige, 
Estland, Lettland och Litauen erbjuder vi ett brett utbud av finansiella tjänster och produkter. Swedbank har drygt 7 miljoner privatkunder och ca 600 000 
företags- och organisationskunder med 186 kontor i Sverige och 125 kontor I de baltiska ländema. Koncemen har även verksamhet I övriga Norden, USA 
och Kina. Den 31 december 2018 uppgick balansomslutningen till 2 246 miljarder kronor. Läs mer pa www swedbank se 
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Swedbank har, med godkännande fran styrelse och vd inlett en omfattande intern utredning av 
bankens historiska efterlevnad av regelverken. Utredningen omfattar motverkan av penningtvatt och 
styrningsrutiner inom Swedbank och dess baltiska dotterbolag. Utredningen görs med stöd av 
erfarna externa rådgivare och bevistekniker samt i samarbete med relevanta myndigheter. 


Utredningen kommer bland annat inkludera preliminära slutsatser från tidigare utredningar och 
förväntas bli tidskrävande att färdigställa. Swedbank kan inte förutse resultatet av denna utredning, 
men kommer ta ställning till de slutsatser som dras under det pågående analysarbetet. Swedbank 
kommer att samarbete med berörda myndigheter kring de slutsatser som utredningen presenterar. 


För mer information: 
Unni Jerndal, presschef, Swedbank, tfn: +46 73 092 11 80 


Detta meddelande gäller offentliggörande av insiderinformation 

Swedbank AB (publ) ska offentliggöra denna information enligt 
Marknadsmissbruksförordningen (EU) nr 596/2014, lagen (2007:528) om 
värdepappersmarknaden, lagen (1991:980) om handel med finansiella instrument och 
Nasdaq Stockholms regelverk för emittenter. Informationen lämnades för offentliggörande 
den 5 april 2019, kl xx.xx. 


Swedbank främjar en sund och hållbar ekonomi for de många manniskoma, hushållen och företagen. Som en ledande bank på hemmamarknadema Sverige, 
Estland, Lettland och Litauen erbjuder уі ett brett utbud av finansiella tjänster och produkter. Swedbank har drygt 7 miljoner privatkunder och ca 600 000 
företags- och organisationskunder med 186 kontor i Sverige och 125 kontor i de baltiske ländema. Koncernen har även verksamhet I övriga Norden, USA 
och Kina. Den 31 december 2018 uppgick balansomsiutningan ШІ 2 246 miljarder kronor. Läs mer på www swedbank se 
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From: Unni Jerndal 

Sent: den 6 april 2019 14:12 

To: Gabriel Francke Rodau; Ragnar Gustavii; Eva De Falck; Gregori Karamouzis 
Subject: FW: senaste 


Har ar de sista versionerna av prm ang insiderfraga som behöver kommuniceras. 

Ser att det vore bra med en taktisk plan dar denna och ev andra frågor som behöver ”vädras” tas om 
hand på ett sätt så att bolagsledningens agerande blir genomtänkt, resolut och konsekvent. Och bidrar 
till att vi tar steg mot att fa ett avslut pa krisen. 


Denna release innehaller information som kommer att vacka manga fragor som kan skada bolaget om 
inte någon ledande företrädare med lugn och sakliga argument - samt ett stort matt av ödmjukhet - kan 
svara och förklara vad det som star i releasen innebär. 


| den situation vi star i nu måste vi börja leva мага värderingar. Om vi gar ut med detta men inte svarar pa 
frågor sa blir det en ny version pa ”mörka” och "obegriplig". 


Basta 
Unni 


From: Unni Jerndal 

Sent: den 5 april 2019 15:50 
To: Eva De Falck 

Subject: senaste 


Eva 


Jag gjorde en sista ändring i sista stycket på den svenska versionen. Tror att det blev bättre. Men kolla 
innan jag skickar vidare. 


Basta 
Unni 


Unni Jerndal 
Press Officer 
Group Communication 


Swedbank AB (publ) 
SE-105 34 Stockholm 
Visit: Landsvägen 40, Sundbyberg 


Dir: +46 (0)8 5859 7640 
Mob: +46 (0)730921 180 
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Eva de Falck Al 


Specification Identification 


The Board of Directors - Swedbank AB 5 19/19 Extra 


Present: Ulrika Francke, Chair 
Bodil Eriksson 
Kerstin Hermansson 
Bo Johansson 
Anna Mossberg 
Peter Norman 
Siv Svensson 
Magnus Uggla 


Camilla Linder (by telephone) 
Roger Ljung 


Anders Karlsson, CEO 
Ingrid Harbo, CAE 
Eva de Falck, Secretary of the Board of Directors 


Apologies of 

absence: Mats Granryd 

Date: 10 April 2019 

Venue: Swedbank HQ, Landsvägen 40, Sundbyberg 
81 OPENING OF THE MEETING 


The Chair, Ulrika Francke, opened the meeting and welcomed everybody. 


There is also a plan to replace the current Chief Compliance Officer, Cecilia Hern vist, with the current 
CAE, Ingrid Harbo as acting Chief Compliance Officer. 
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Eva de Falck 10 April 2019 
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The Board of Directors – Swedbank АВ S 19/19 Extra 
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Swedbank @ Minutes 


INTERNAL AND CONFIDENTIAL 


Author Date 
Specification Identification 


REMUNERATION TO ACTING CHIEF COMPLIANCE OFFICER 


CLOSING OF THE MEETING 


The Chair, Ulrika Francke asked the Board mernbers to revert to her on their availability to be re- 
elected as Directors of the Board of Swedbank AB (publ) at a possible upcoming Extra General ' 
Meeting. 


Ulrika Francke also asked everyone to send their input regarding external communication to Bodil 
Eriksson who will forward the input received to Kreab. 


As no further matters were at hand, the Chair, Ulrika Francke, declared the meeting, which was 
opened at 18.00, closed at 20.45. 


Minutes kept by: 


Eva de Falck 


| Inkomna handlingar vid förhör med Eva De Falck , 2020-10-23 10:24 diarienr: 9000-К822-19 517 | 


Swedbank @ Minutes 


INTERNAL AND CONFIDENTIAL 


10 April 2019 5(5 


Identification 


S 19/19 Extra 


Author 
Eva de Falck 
Specification 


The Board of Directors - Swedbank АВ” 


Checked by: 


Ulrika Francke 


Siv Svensson 


[Inkomna handlingar vid förhör med Eva De Falck , 2020-10-23 10:24 diarienr: 9000-K822-19 


ste] 


© Swedbank 


Inkomna handlingar vid förhör med Eva De Falck , 2020-10-23 10:24 diarienr: 9000-К822-19 


Communication plan — managerial and 
organisational changes 


Version: 3 
2019-04-10 


1.1 Background 

Recent events have shed light on the importance of further strengthening our 
group capabilities within the area of financial crime. As previously communicated 
we have decided to further invest in a new internal unit, Financial Crime 
Intelligence, to focus on finding and handling criminal activities that are the basis 
for money laundering. 


Being active in four different home markets requires us to have a unified approach 
on how to manage financial crime, and ensure that all business areas get the 
support necessary. A centralised financial crime intelligence unit will make it 
possible to gather and distribute information throughout the group and support the 
group in defining strategies, performing investigations and defining appropriate 
mitigating actions. 


Author/Administrator: Gabriel Francke Rodau Specification/Version: 3 
Department: Information class: Confidential 


Restricted access (if applicable): CEO, Head of Group Communication and others with the permission of the before 
mentioned 
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1.3 Тіте plan 
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1.4 Press release 


11 April 2019 


Swedbank sets up Financial crime intelligence unit 


Confidential 
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1.5 Internal article 
Swedbank sets up Financial crime intelligence unit 
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Version: 5 
2019-04-10 


1.1 Background 

Recent events have shed light on the importance of further strengthening our 
group capabilities within the area of financial crime. As previously communicated 
we have decided to further invest in a new internal unit, Financial Crime 
Intelligence, to focus on finding and handling criminal activities that are the basis 
for money laundering. 


Being active in four different home markets requires us to have a unified approach 
on how to manage financial crime, and ensure that all business areas get the 
support necessary. A centralised financial crime intelligence unit will make it 
possible to gather and distribute information throughout the group and support the 
group in defining strategies, performing investigations and defining appropriate 
mitigating actions. 


Author/Administrator: Gabriel Francke Rodau Specificatlon/Version: 5 
Department: Information class: Confldentlal 


Restricted access (If applicable): CEO, Head of Group Communication and others with the permission of the before 
mentioned 
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1.3 Time plan 


Author/Administrator: Gabriel Francke Rodau Specificatlon/Version: 5 
Department: Group Communication Information class: Confidential 


Restricted access (if applicable): CEO, Head of Group Communication and others with the permission of the before 
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1.4 Press release 


11 April 2019 


Swedbank sets up Financial crime intelligence unit 


Author/Administrator: Gabriel Francke Rodau Specification/Version: 5 
Department: Group Communication Information class: Confidential 


Restricted access (If applicable): CEO, Head of Group Communication and others with the permission of the before 
mentioned 
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Communication plan – managerial and 
organisational changes 


Version: 7 
2019-04-10 


1.1 Background 

Recent events have shed light on the importance of further strengthening our 
group capabilities within the area of financial crime. As previously communicated 
we have decided to further invest in a new internal unit, Anti-Financial Crime 
(AFC), to focus on finding and handling criminal activities that are the basis for 
money laundering. 


Being active in four different home markets requires us to have a unified approach 
on how to manage financial crime, and ensure that all business areas get the 
support necessary. A centralised AFC unit will make it possible to gather and 
distribute information throughout the group and support the group in defining 
strategies, performing investigations and defining appropriate mitigating actions. 
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1.3 Time plan 
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1.4 Press release 


12 April 2019 


Swedbank establishes an Anti-Financial Crime unit 


Author/Administrator: Gabriel Francke Rodau Specification/Version: 7 
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1.5 Internal article 
[To be updated based on the press release] 
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Version: 10 
2019-04-11 


1.1 Background 
Recent events have shed light on the importance of further strengthening our 


group capabilities within the area of financial crime. As previously communicated 
we have decided to further invest in a new internal unit, Anti-Financial Crime 
(AFO), to focus on finding, preventing and handling criminal activities that are the 


basis for money laundering. 


Being active in four different home markets requires us to have a unified approach 
on how to manage and prevent financial crime, and ensure that all business areas 
get the support necessary. А centralised AFC unit will make it possible to gather 
and distribute information throughout the group and support the group in defining 
strategies, performing investigations and defining appropriate mitigating actions. 
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12 April 2019 


Swedbank establishes an Anti-Financial Crime unit 
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1.5 Press release — Swedish version 
Swedbank etablerar enhet fór att bekámpa ekonomisk 
brottslighet 
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1.22 Press release 


25 April, 2019 


Swedbank establishes a dedicated Anti-Financial Crime 
unit and makes changes in Group Executive Committee 
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Pressmeddelande 


25 april 2019 


Swedbank etablerar särskild enhet för att bekämpa 
ekonomisk brottslighet och vidtar förändringar 
i koncernledningen 


Author/Administrator: Gabriel Francke Rodsu Spacitication/Verslon: 18 
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Version 11 (190423) 


Vd-kommentar 


Årets första kvartet har till stor del präglats av 

uppgifter om att Swedbank her bruslil i arbetet med att 
förhindra penningtvatl. Bankens anseende har tagit 
skada och som tillförordnad vd är del min främsta 
uppgift att nu genomföra åtgärder som gör ай м kan 
börja ålervinna förtroende hos kunder, ägare och andra 
intressenter. 


Tidigare interna utredningar har Indikerat brister i 
Swedbanks arbete mot penningtvätt, Dessa Innefattar 
att vissa kunder har matchats mot listor på personer och 
företag som förekommit I tidigare penningtvättsfall, 
brister i kundkännedom kopplad ull vissa kunder, 
exempelvis avseende verkligt ägande och pengars 
ursprung, samt bristande granskning och rapportering 
till myndigheter avseende vissa misstänkta 
transaktioner. 


För att gå till botten med vad som hänt pågår nu en 
fördjupad Intern utredning, som ska utnyttja Innehållat I 
tidigare genomförda intema utredningar. Därutöver 
samarbetar Swedbank fullt ut med de myndigheter i 
Sverige, USA och de baltiska länderna som genomför 
ollka undersökningar. 


Ny enhet för att bekämpa ekonomisk brottslighet 
För att förstärka vårt fortsatla arbete mot ekonomisk 
brottslighet I ollka former skapar vi nu en ny 
koncernövergripande enhet inom banken. Enheten får 
namnet Anti-Financial Crime unit (AFC) och kommer att 
arbeta med att motverka penningtvätt, 
terrorismfinanslering och bedrägerler samt även med 
cybersäkerhet, Informatlonssäkerhet och fysisk 
säkerhet. Den nya enheten kommer också ай 
koordinera Intemt Initierade utredningar samt se över 
interna processer och rutiner och har ansvar för 
samarbetet med ansvariga myndigheter inom området. 


Banker spelar en central roll i kampen mot penningtvätt. 
Det är alla bankers ansvar att känna sina kunder, atl 
rapportera misstänka transaktioner ШІ myndigheterna 
och se till alt medarbetare följer lagar och regler. 


För att Swedbank ska förtjäna förtroende från vår 
omvärld krévs att vårt arbete mot penningtvätt ständigt 
förbättras. Över tid har vi löpande stärkt våra metoder. 
2016 Intensiflerades arbetet genom etl särskilt program 
mo! penningtvätt, med särskilt fokus på de baltiska 
marknademe. Skärpta rutiner ledde till att många 
kundtörhållandon avvecklades. 


Men lika lite som någon annan bankchef kan Jag 
garantera att уап arbete mot penningtvätt är utan 
brister. Kapplöpningen med de kriminella pågår hela 
tiden. De utredningar som nu pågår kommer att ge oss 
viktiga svar på om vl behöver vidia ytterligare åtgärder. 
Därtill vill vi också se elt närmare samarbete mellan 
banker, olika myndigheter och finanspolisen för att 
bekämpa det samhällsproblem som penninglväll utgör. 


Satsningar för ökat förtroende och kundvärde 
Utöver den intema utredningen och den organisatoriska 
förändringen kommer vi även att göra ett antal 
omprioriteringar med syfte att förbättra våra processer 
och öka kundvärdet. Vårt starka finanslella utgångsläge 
möjliggör satsningar utöver de leveranser vi redan 
planerat för i år. 


Som ett led I arbelet med att förbättra vår bekämpning 
av penningtvätt kommer vi att påskynda projekt som 
syftar ШІ att stärka våra processer och system. 


Vissa pågående projekt som syftar ШІ att digitalisera 
vardagliga banktjänster kommer att kosta något mer för 
all kunna slutföras under årel än vad som uppskattades 
Inillalt. VI väljer att fortsätta med dessa I oförändrad takt 
шИгап vår övartygelse om atl satsningarna kommer att 
öka kundvärdet. 


Sammantaget bedöms dessa Initiativ leda till ökade 
kostnader på cirka en miljard kronor under året, utöver 
vårt redan kommunicerade mål om att underliggande 
kostnader ska understiga 17 miljarder kronor under 
2019. Vårt finansiella mal om en avkastning pa eget 
kapital på minst 15 procent kvarstår. 


Starkt finansiellt resultat 

I kontrast till förra årets avslutning har 
marknadsrérelsema магіі gynnsamma under årets första 
kvartal. Globala börser har utvecklats positivi och 
kreditspreadar har gått ihop. Tillväxtutsikterna har 
emellertid justerats ned något, delvis som en följd av 
ostikerheten kring de pågående handelskonfliktems och 
Brexil-forhandlingama. 


Den дода marknadsutvecklingen har påverkat vårt 
finansiella resultat positivt. Rantenettot har stärkte ШІ 
följd av en lägre resolutlonsavgift och högre korta 
marknadsräntor. VI ser fortsatt god lánetillváxt ра alla 
våra hemmamarknader, men i något lägre takt, 
framförallt I den svenska bolåneportföljen. Den svenska 
bolánemarknaden är fortsalt stabil. 


Provislonsnettot är casongmasstgt lägre men 
underliggande har framförallt kapitalfórvaltningen 
levereral ett starkt resultat, med bade god 
vardeutveckling och fortsatla inflóden. 
Marknadsrürelsema I kvarlalel har framföralll stärkt 
nettoresultatet från fInansləlla poster ШІ följd av högre 
aktivitet och positiva värderingsetfekter. 


Kreditkvallteten är fortsatt god pa alla vara 
hemmamarknader. Vår kapilal- och likviditetsposition ar 
stark med god marginal till Finansinspektionens 
minimikrav. 


Slulligen vill Jag rikla ett stort tack Ш alla medarbetare 
som under den tuffa perlod vi har gåt! Igenom har mött 
oroliga kunder ра bästa möjliga sätt och varit goda 
ambassadörer för banken. Swedbank står stadigt 
genom våra starka värderingar. Det är på den grunden 
vi dag för dag bygger en ännu bättre bank 


! 
А. Vai 


Anders Karlsson 
Tillfórordnad verkställande direktör och koncemchef 


Commented [EDF1]: Som jag framförde Idag, hade det vart 
önskvärt att паг få mod något om statusen | den svensku 
verksamheten för titt a) undvika fortsatt riskexponering I den 

| delen och b) kunna река på att vi nämnt dot, СОА bekräftar 

| synpunkten och jag vill därför ta upp den Igen, Avan om ni från 

{ kommunikationssynvinkel into (уског dot är tampligt. 
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CEO Comment 


The first quarter of the year was largely characterized by 
reports of shortcomings іл Swedbank's anti-money 
laundering work. The bank's reputation has been 
damaged and as acting CEO my highest priorily Is to 
Implement measures that will enable us lo restore trust 
amongst customers, owners and other stakeholders. 


Previous Intemal Investigations have indicated 
shortcomings in Swedbank's anti-money laundering 
work. These include reports that certaln customers have 
maiched agalnst Іі of persons and entitles mentioned 
in connectlon with previously known money laundering 
cases, weaknesses In KYC connected to certaln 
custorners, e.g. relating to beneficial ownership and 
source of funds, as well as absence of Investigations 
and reporis to the authoritles on certain suspicious 
transactions. 


In order to get to the bottom of the matter, an in-depth 
internal Investigation 18 now underway which will use 
information from previous Internal Investigations. In 
addition, Swedbank Is fully cooperating with the 
authorities in Sweden, the U.S. and the Baltic caunirles 
In thelr respective Investigations. 


A new unit to combat financlal crime 

In order to strengthen our ongoing work of preventing 
and combating all aspects of financial crime we are now 
establishing a new group wide unit within the bank, the 
Anti-Financial Crime (AFC) unit, AFC will focus on antl- 
money laundering (AML), counter-terrorism financing 
and fraud prevention, as well as cyber security, 
Information security and physical security. The new unit 
will also coordinate internally Initiated Investigations, 
review Intemal processes and routines and manage 
cooperation with the authorities within the AML area. 


Banks play a central role in combating money 
laundering, All banks are responsible for knowing their 
customers, for reporting suspicious transactions to the 
authorities and for ensuring that all employees adhere to 
laws and regulations. 


For Swedbank to deserve the trust of customers, 
authorities, investors, employees and other 
stakeholders, continuous Improvement In In our anti- 
money laundering work Is required. Over the years, we 
have enhanced our methods continuously. In 2016 our 
work was Inlensifled through a special anti-money 
laundering program, with particular focus on the Baltic 
markets, More stringent procedures led to many 
customers being off-boarded. 


However, no bank executive, me Included, can 
guarantee that all our AML work IS flawless. The race 
against criminals Is constantly ongoing. The 
Investigations now underway will provide us with 
important answers regarding any further measures that 
wa may need to take. In addition, we would also like to 
see closer collaboration between banks, authoritles and 
the financial police. In order to combat the problem 
inherent In society that money laundering poses. 


Increasing trust and customer value 
In addition to Internal Investigations and the 
organisational changes, we will make a number of 


reprioritisations with the alm to Improve our processes 
and increase customer value. Our strong financial 
position enables further investments on top of those 
planned for the year. 


As part of the effort lo Improve our AML work, we will 
accelerate projecis aimed at strengthening our 
processes and systems. 


Some of our ongoing projects that aim to digitize 
everyday banking services will cost more than Initially 
estimated In order to be completed during the year. 
Based on our bellef that these Investments will Increase 
customer value, we have chosen to continue with the 
projects at the current pace. 


Altogether, these Initiatives are estimated to Increase 
costs by approximately SEK 1 billion during the year, in 
addition to our previously communicated goal of keeping 
underlying expenses below SEK 17 billion In 2019. Our 
financial goal to generate a return on equity of at least 
15 per cent remains. 


A strong financial result 

In contrasl to the end of last year, markei movemanis 
have been favourable during the firet quarter of 2019. 
Global stock exchanges have developed positively, and 
credit spreads have tightened. Growth prospecis have, 
however, been revised down, partly as a result of the 
uncertainty surrounding ongolng trade conflicts and the 
Brexit negotiations. 


The market development has had a positive impact on 
our financial performance. Net interest income has been 
strengthened as a result of a lower resolution fund fee 
and higher short-term market rates, We continue to see 
а positive loan growth іп all our home markets, but at a 
somewhat lower pace, especially in the Swedish 
morigage loan portfolio. The Swedish morigage market 
remain stable. 


Net commission Income is seasonally lower, but asset 
management has delivered strong earnings, with 
positive increase іп value and continued inflows, The 
market movements during the quarter have primarily 
strengthened net profils from financial items as a result 
of higher activity and positive valuation effects. 


Credit quality remains resilient in all our home markets. 
Our capital and liquidity position is strong with а good 
buffer to the minimum requirements stated by the 
Swedish Financial Supervisory Authority. 


Lastly, | would like to extend my sincerest thanks to all 
employees who, during this challenging period, have 
assisted worrled customers In the best possible way and 
have been excellent ambassadors for the bank. 
Swedbank stands on solid ground, thanks to our strong 
values. It is on this foundation we will continue to bulld 
an even better bank, day after day. 


Anders Karlsson 
Acting President and CEO 
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Swedbank establishes a dedicated Anti-Financial Crime 
unit and makes changes in Group Executive Committee 


Author/Administrator: Gabriel Francke Rodau Specification/Version: 23 
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Annika Winther 

From: Eva De Falck | 

Sent: den 8 maj 2019 09:03 | 

То: Annika Winther | 

Subject: FW: MAR-mótet på onsdag * | 

Attachments: cid 2878988[1].pdf; TOR CMI.pdf | 
| 
| 


From: Eva De Falck | 
Sent: den 7 maj 2019 21:48 | 
То: Eva De Falck 
Subject: FW: MAR-mötet på onsdag | 


From: Eva Ре Falck | 
Sent: den 7 maj 2019 17:02 | 
To: Gabriel Francke Rodau; Tomas Hedberg; Gregori Karamouzis | 
Subject: FW: MAR-mötet på onsdag | 


Se nedan och bif. Lite tankar runt CMI framåtriktat. 


Mvh 
Eva 


From: Eva De Falck 

Sent: den 7 maj 2019 13:01 

To: Anders Karlsson; 'Biorn Riese' 
Cc: Åsa Andersson; Alexandra Kaijser 
Subject: MAR-mötet på onsdag 
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51 OPENING OF THE MEETING 


The Chair, Lars Idermark, opened the meeting and welcomed everybody. It was noted that all 
presentations shown at the meeting will be uploaded on Directors Desk directly after the meeting, 


The Chair, Lars Idermark Informed that the Board evaluation for 2018 will be made іп late August. 
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In addition to the written inquiry, Lars Idermark will have an interview with each one of the Board 
members. The result will be presented at the August Board meeting. 


CONFLICT OF INTEREST TO REPORT AS REGARDS ANY OF THE ITEMS ON TODAY'S 


AGENDA 
APPROVAL OF THE MINUTES 
CEO UPDATE 

S 4a CEO REPORT 


The CEO, Birgitte Bonnesen, referred to the CEO report that had been sent out prior to the meeting 
and briefly commented some of the items in the report. 


Danske Bank in Estonia is suspected to have been used for money laundering amounting to billions 
of DKK with connection to Russia and in addition suspected to have been involved in illegal arms 


trade to North Korea and Iran. In light of this news, Swedbank is looking into transactions and other 
links, if any, to Danske Bank in Estonia. 


Since everyone had read the CEO report, Birgitte Bonnesen asked whether anyone had any 
questions or comments as to the report. 
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The Chair, Lars Idermark, thanked Birgitte Bonnesen for the update. 


4 § 4b CENTRAL BANKS 
6 4c HR UPDATE 
6 4c! REMCO SUMMARY 


§ 4c li EKEN AND IP; Q2 2018 PROPOSED ALLOCATION 


8 4c Ili IP; Q2 RISK ASSESSMENT 


566] 


_567 


| Styrelseprotokoll 17 juli 2018 , 2020-06-08 09:15 diarienr: 9000-K822-19 


Minutes 


INTERNAL AND CONFIDENTIAL 


Date Page 
17 July 2018 4 (20) 


Author 
Eva de Falck 
Specification 

The Board of Directors - Swedbank AB 


Identification 


5 09/18 


84сіу, ЕКЕМ AND ІР; TERMS АМО CONDITIONS 2018 


Styrelseprotokoll 17 juli 2018, 2020-06-08 09:15 diarienr: 9000-К822-19 


568 | 


. 


= 7% Minutes 


INTERNAL AND CONFIDENTIAL 


Author Date Page 
Eva de Falck 17 |Шу 2018 5 (20) 
Specification Identification 

The Board of Directors - Swedbank AB S 09/18 


S 4c v. MATERIAL RISK TAKERS 2018 


§ 4c vi. SALARY CHANGE FOR GEC MEMBERS 


569] 


[Styrelseprotokoll 17 juli 2018 , 2020-06-08 09:15 diarienr: 9000-K822-19 


Minutes 


INTERNAL AND CONFIDENTIAL 


Date Page 

17 July 2018 
Identification 

5 09/18 


Author 

Eva de Falck 

Specification 

The Board of Directors ~ Swedbank AB 


8 4c vii, SWEDBANK BALTIC PENSION PLAN 


— E) 


Styrelseprotokoll 17 juli 2018 , 2020-06-08 09:15 diarienr: 9000-К822-19 


E Minutes 


INTERNAL AND CONFIDENTIAL 


Author Date Page 

Eva de Falck 17]uly zo1e 
Specification Identification 

The Board of Directors - Swedbank AB 5 09/18 


_ 5 4c viii. CEO TARGETS; Q2 2018 FOLLOW UP 
| 
i 
6 4c ix. AGREEMENT WITH RELATED PARTY 


| li iari j 571 
Styrelseprotokoll 17 juli 2018, 2020-06-08 09:15 diarienr: 9000-K822-19 _ | 


Minutes 

INTERNAL AND CONFIDENTIAL 
Author Date Page 
Eva de Falck 
Specification Identification 
The Board of Directors - Swedbank AB 


85 СОМРЦАМСЕ UPDATE 


55а COMPLIANCE REPORT 02 2018 INCLUDING REGULATORY WATCH АМО 
REGULATORY СОМТАСТ5 


Styrelseprotokoll 17 juli 2018 , 2020-06-08 09:15 diarienr: 9000-K822-19 === 572 | 


ON 


Minutes 
€ nu 


INTERNAL AND CONFIDENTIAL 


Author Date Page 
Specification Identification 
The Board of Directors - Swedbank AB 


КТ 
FEST 


The Chair, Lars Idermark, thanked Cecilia Herngvist for the presentation and the Board of Directors 
made a note of the Compliance report for 02 2018, 
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8 6a RISK AND CAPITAL COMMITTEE SUMMARY 
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81 OPENING OF THE MEETING 


The Chalr, Lars Idermark, opened the meeting and welcomed everybody. It was noted that all 
presentations shown at the meeting will be uploaded on Directors Desk directly after the meeting. 


The Chair also welcomed Áke Skoglund to his first meeting with the Board of Directors. 
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Item § 4c, Open Banking and data aggregation, was postponed until after lunch due to the need of 
Lotta Lovén's attendance in another meeting, however this will not be reflected in these minutes. 


§2 CONFLICT OF INTEREST TO REPORT AS REGARDS ANY OF THE ITEMS ON TODAY'S 
AGENDA 


§3 APPROVAL OF THE MINUTES 


54 CEO UPDATE 


§ 4a CEO REPORT 


The CEO, Birgitte Bonnesen, referred to the CEO report that had been sent out prior to the meeting 
and asked whether anyone had any comments or questions as to the report. 
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The Chair, Lars Idermark, thanked Birgitte Bonnesen for the update. 
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- 611 NEXT MEETING MONDAY 22 OCTOBER 2018 


The Chair, Lars Idermark, reminded the Board of Directors that the next ordinary meetlng is 
scheduled on Monday 22 October 2018, starting at 14.00. The meeting will be held at 
Swedbank's Head Office in Sundbyberg, in the Board room on floor B. 

611 CLOSING OF THE MEETING 


As no further matters were at hand, the Chair, Lars Idermark, declared the meeting, which was 
opened at 10.00, closed at 15.40, i 
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81 OPENING OF THE MEETING 


The Chair, Lars Idermark, opened the meeting and welcomed everybody. It was noted that all 
presentations shown at the meeting will be uploaded on Directors Desk directly after the meeting. 


Lars Idermark also informed that the CEO-update today will focus on Anti Money Laundering 
actions and Money Laundering mitigating measures in different parts of Swedbank Group. 
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Present: Ulrika Francke, Chair 
Bodil Eriksson 
Kerstin Hermansson 
Bo Johansson 
Anna Mossberg 
Peter Norman 
Siv Svensson 
Magnus Uggla 


Camilla Linder (by telephone) 
Roger Ljung 


Anders Karlsson, CEO 
Ingrid Harbo, CAE 
Eva de Falck, Secretary of the Board of Directors 


Apologies of 

absence: Mats Granryd 

Date: 10 April 2019 

Venue: Swedbank HQ, Landsvägen 40, Sundbyberg 
81 OPENING OF THE MEETING 


The Chair, Ulrika Francke, opened the meeting and welcomed everybody. 


There is also a plan to replace the current Chief Compliance Officer, Cecilia Hernqvist. with the current 
CAE, — Harbo as = Chief Compliance пите ЛУ о SS 
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53 REMUNERATION ТО АСТІМС CHIEF COMPLIANCE OFFICER 


84 CLOSING OF THE MEETING 


The Chair, Ulrika Francke asked the Board members to revert to her on their availability to be re- 
elected as Directors of the Board of Swedbank AB (publ) at a possible upcoming Extra General 
Meeting. 


Ulrika Francke also asked everyone to send their input regarding external communication to Bodil 
Eriksson who will forward the input received to Kreab. 


As no further matters were at hand, the Chair, Ulrika Francke, declared the meeting, which was 
opened at 18.00, closed at 20.45, 
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